Loading...
background

CMMC L3

CMMC L3

CMMC L3

CMMC Level 3 is the Department of Defense's mandatory cybersecurity standard for contractors handling Controlled Unclassified Information (CUI). It requires full implementation of all 110 security controls outlined in NIST SP 800-171 across 14 distinct domains.

Controls:

Limit system access to authorized users, processes, and devices. Control the types of transactions and functions authorized users may execute. Applies to all CUI systems and environments.

  • AC.L1-3.1.1 - Authorized User Access

    Requirement AC.L1-3.1.1 (CMMC Level 2 (L2 Baseline)): Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).

  • AC.L1-3.1.2 - Authorized User Access

    Requirement AC.L1-3.1.2 (CMMC Level 2 (L2 Baseline)): Limit system access to the types of transactions and functions that authorized users are permitted to execute.

  • AC.L2-3.1.3 - CUI Flow Control

    Requirement AC.L2-3.1.3 (CMMC Level 2 (L2 Baseline)): Control the flow of CUI in accordance with approved authorizations.

  • AC.L2-3.1.4 - Separation of Duties

    Requirement AC.L2-3.1.4 (CMMC Level 2 (L2 Baseline)): Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

  • AC.L2-3.1.5 - Least Privilege

    Requirement AC.L2-3.1.5 (CMMC Level 2 (L2 Baseline)): Employ the principle of least privilege, including for specific security functions and privileged accounts.

  • AC.L2-3.1.6 - Least Privilege - Non-Privileged Functions

    Requirement AC.L2-3.1.6 (CMMC Level 2 (L2 Baseline)): Use non-privileged accounts or roles when accessing non-security functions.

  • AC.L2-3.1.7 - Privileged Function Audit

    Requirement AC.L2-3.1.7 (CMMC Level 2 (L2 Baseline)): Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.

  • AC.L2-3.1.8 - Unsuccessful Logon Attempts

    Requirement AC.L2-3.1.8 (CMMC Level 2 (L2 Baseline)): Limit unsuccessful logon attempts.

  • AC.L2-3.1.9 - Privacy and Security Notices

    Requirement AC.L2-3.1.9 (CMMC Level 2 (L2 Baseline)): Provide privacy and security notices consistent with CUI rules.

  • AC.L2-3.1.10 - Session Lock

    Requirement AC.L2-3.1.10 (CMMC Level 2 (L2 Baseline)): Use session lock with pattern-hiding displays after a period of inactivity.

  • AC.L2-3.1.11 - Session Termination

    Requirement AC.L2-3.1.11 (CMMC Level 2 (L2 Baseline)): Terminate (automatically) a user session after a defined condition.

  • AC.L2-3.1.12 - Remote Access - Monitor and Control

    Requirement AC.L2-3.1.12 (CMMC Level 2 (L2 Baseline)): Monitor and control remote access sessions.

  • AC.L2-3.1.13 - Remote Access - Cryptographic Protection

    Requirement AC.L2-3.1.13 (CMMC Level 2 (L2 Baseline)): Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

  • AC.L2-3.1.14 - Remote Access - Access Control Points

    Requirement AC.L2-3.1.14 (CMMC Level 2 (L2 Baseline)): Route remote access via managed access control points.

  • AC.L2-3.1.15 - Remote Privileged Commands

    Requirement AC.L2-3.1.15 (CMMC Level 2 (L2 Baseline)): Authorize remote execution of privileged commands and access to security-relevant information via remote access only for documented operational needs.

  • AC.L2-3.1.16 - Wireless Access - Authorization

    Requirement AC.L2-3.1.16 (CMMC Level 2 (L2 Baseline)): Authorize wireless access prior to allowing such connections.

  • AC.L2-3.1.17 - Wireless Access - Authentication and Encryption

    Requirement AC.L2-3.1.17 (CMMC Level 2 (L2 Baseline)): Protect wireless access using authentication and encryption.

  • AC.L2-3.1.18 - Mobile Device Control

    Requirement AC.L2-3.1.18 (CMMC Level 2 (L2 Baseline)): Control connection of mobile devices.

  • AC.L2-3.1.19 - CUI Encryption on Mobile Devices

    Requirement AC.L2-3.1.19 (CMMC Level 2 (L2 Baseline)): Encrypt CUI on mobile devices and mobile computing platforms.

  • AC.L2-3.1.20 - External System Connections

    Requirement AC.L2-3.1.20 (CMMC Level 2 (L2 Baseline)): Verify and control/limit connections to external systems.

  • AC.L2-3.1.21 - Portable Storage on External Systems

    Requirement AC.L2-3.1.21 (CMMC Level 2 (L2 Baseline)): Limit use of portable storage devices on external systems.

  • AC.L2-3.1.22 - Publicly Accessible Systems - CUI Control

    Requirement AC.L2-3.1.22 (CMMC Level 2 (L2 Baseline)): Control CUI posted or processed on publicly accessible systems.

  • AC.L3-3.1.2e - Dynamic Access Control

    Requirement AC.L3-3.1.2e (CMMC Level 3 (L3 Enhanced)): Employ dynamic access control approaches (e.g., attribute-based access control) that allow access decisions to incorporate additional factors.

  • AC.L3-3.1.3e - Automated Access Control Enforcement

    Requirement AC.L3-3.1.3e (CMMC Level 3 (L3 Enhanced)): Use automated mechanisms to enforce access control policies.

Ensure managers, administrators, and users are aware of security risks and trained to carry out assigned information security responsibilities including recognition of advanced threats.

  • AT.L2-3.2.1 - Role-Based Security Awareness

    Requirement AT.L2-3.2.1 (CMMC Level 2 (L2 Baseline)): Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities.

  • AT.L2-3.2.2 - Role-Based Security Training

    Requirement AT.L2-3.2.2 (CMMC Level 2 (L2 Baseline)): Ensure that personnel are trained to carry out their assigned information security responsibilities.

  • AT.L2-3.2.3 - Insider Threat Awareness

    Requirement AT.L2-3.2.3 (CMMC Level 2 (L2 Baseline)): Provide security awareness training on recognizing and reporting potential threats (e.g., social engineering attacks).

  • AT.L3-3.2.1e - Advanced Threat Awareness - TTPs

    Requirement AT.L3-3.2.1e (CMMC Level 3 (L3 Enhanced)): Provide awareness training focused on recognizing and responding to threats from adversarial tactics, techniques, and procedures (TTPs).

Create, retain, and review system audit logs to enable monitoring, analysis, investigation, and reporting of unauthorized activity. Employ SIEM for centralized detection and correlation.

  • AU.L2-3.3.1 - Audit Log Creation and Retention

    Requirement AU.L2-3.3.1 (CMMC Level 2 (L2 Baseline)): Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

  • AU.L2-3.3.2 - Individual User Traceability

    Requirement AU.L2-3.3.2 (CMMC Level 2 (L2 Baseline)): Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.

  • AU.L2-3.3.3 - Audit Log Review and Update

    Requirement AU.L2-3.3.3 (CMMC Level 2 (L2 Baseline)): Review and update logged events.

  • AU.L2-3.3.4 - Audit Log Failure Alerting

    Requirement AU.L2-3.3.4 (CMMC Level 2 (L2 Baseline)): Alert in the event of an audit logging process failure.

  • AU.L2-3.3.5 - Audit Log Analysis and Correlation

    Requirement AU.L2-3.3.5 (CMMC Level 2 (L2 Baseline)): Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

  • AU.L2-3.3.6 - Audit Report Generation

    Requirement AU.L2-3.3.6 (CMMC Level 2 (L2 Baseline)): Provide audit record reduction and report generation to support on-demand analysis and reporting.

  • AU.L2-3.3.7 - Authoritative Time Source

    Requirement AU.L2-3.3.7 (CMMC Level 2 (L2 Baseline)): Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

  • AU.L2-3.3.8 - Audit Log Protection

    Requirement AU.L2-3.3.8 (CMMC Level 2 (L2 Baseline)): Protect audit information and audit tools from unauthorized access, modification, and deletion.

  • AU.L2-3.3.9 - Audit Management Privilege Restriction

    Requirement AU.L2-3.3.9 (CMMC Level 2 (L2 Baseline)): Limit management of audit logging to a subset of privileged users.

  • AU.L3-3.3.1e - SIEM Deployment

    Requirement AU.L3-3.3.1e (CMMC Level 3 (L3 Enhanced)): Employ a Security Information and Event Management (SIEM) system to centralize log collection, analysis, and reporting to detect, correlate, and respond to security events and anomalous activities.

Periodically assess security controls, develop plans of action, monitor controls on an ongoing basis, and maintain system security plans. Use authorized third-party assessors for comprehensive evaluations.

  • CA.L2-3.12.1 - Security Control Assessment

    Requirement CA.L2-3.12.1 (CMMC Level 2 (L2 Baseline)): Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

  • CA.L2-3.12.2 - Plan of Action

    Requirement CA.L2-3.12.2 (CMMC Level 2 (L2 Baseline)): Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

  • CA.L2-3.12.3 - Security Control Monitoring

    Requirement CA.L2-3.12.3 (CMMC Level 2 (L2 Baseline)): Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

  • CA.L2-3.12.4 - System Security Plan

    Requirement CA.L2-3.12.4 (CMMC Level 2 (L2 Baseline)): Develop, document, and periodically update system security plans that describe system boundaries, environments of operation, how security requirements are implemented, and relationships with or connections to other systems.

  • CA.L3-3.12.1e - Comprehensive Third-Party Assessment

    Requirement CA.L3-3.12.1e (CMMC Level 3 (L3 Enhanced)): Employ a security assessment organization that meets the requirements of appropriate law, policy, or regulation to conduct comprehensive security assessments of organizational systems and the environments in which those systems operate.

Establish and maintain baseline configurations and inventories of organizational systems. Enforce security configuration settings and control changes to systems through automated and manual processes.

  • CM.L2-3.4.1 - Baseline Configuration

    Requirement CM.L2-3.4.1 (CMMC Level 2 (L2 Baseline)): Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation).

  • CM.L2-3.4.2 - Security Configuration Settings

    Requirement CM.L2-3.4.2 (CMMC Level 2 (L2 Baseline)): Establish and enforce security configuration settings for information technology products employed in organizational systems.

  • CM.L2-3.4.3 - Change Control

    Requirement CM.L2-3.4.3 (CMMC Level 2 (L2 Baseline)): Track, review, approve, and log changes to organizational systems.

  • CM.L2-3.4.4 - Security Impact Analysis

    Requirement CM.L2-3.4.4 (CMMC Level 2 (L2 Baseline)): Analyze the security impact of changes prior to implementation.

  • CM.L2-3.4.5 - Access Restrictions for Change

    Requirement CM.L2-3.4.5 (CMMC Level 2 (L2 Baseline)): Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

  • CM.L2-3.4.6 - Least Functionality

    Requirement CM.L2-3.4.6 (CMMC Level 2 (L2 Baseline)): Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.

  • CM.L2-3.4.7 - Nonessential Programs Restriction

    Requirement CM.L2-3.4.7 (CMMC Level 2 (L2 Baseline)): Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

  • CM.L2-3.4.8 - Application Whitelisting/Blacklisting

    Requirement CM.L2-3.4.8 (CMMC Level 2 (L2 Baseline)): Apply deny-by-exception (blacklisting) to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

  • CM.L2-3.4.9 - User-Installed Software Control

    Requirement CM.L2-3.4.9 (CMMC Level 2 (L2 Baseline)): Control and monitor user-installed software.

  • CM.L3-3.4.1e - Automated Asset Discovery and Inventory

    Requirement CM.L3-3.4.1e (CMMC Level 3 (L3 Enhanced)): Establish and maintain an accurate, current, and complete inventory of organizational systems, components, and software, including unauthorized software, using automated discovery tools.

Identify and authenticate users, processes, and devices before granting access to organizational systems. Enforce MFA, strong password policies, and replay-resistant authentication mechanisms.

  • IA.L2-3.5.1 - User and Device Identification

    Requirement IA.L2-3.5.1 (CMMC Level 2 (L2 Baseline)): Identify system users, processes acting on behalf of users, and devices.

  • IA.L2-3.5.2 - User and Device Authentication

    Requirement IA.L2-3.5.2 (CMMC Level 2 (L2 Baseline)): Authenticate (or verify) the identities of users, processes, or devices as a prerequisite to allowing access to organizational systems.

  • IA.L2-3.5.3 - Multifactor Authentication

    Requirement IA.L2-3.5.3 (CMMC Level 2 (L2 Baseline)): Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

  • IA.L2-3.5.4 - Replay-Resistant Authentication

    Requirement IA.L2-3.5.4 (CMMC Level 2 (L2 Baseline)): Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

  • IA.L2-3.5.5 - Identifier Management

    Requirement IA.L2-3.5.5 (CMMC Level 2 (L2 Baseline)): Employ identifier management practices that include: binding identifiers to devices, not reusing identifiers for a defined period, and disabling inactive identifiers.

  • IA.L2-3.5.6 - Identifier Deactivation After Inactivity

    Requirement IA.L2-3.5.6 (CMMC Level 2 (L2 Baseline)): Disable identifiers after a defined inactivity period.

  • IA.L2-3.5.7 - Password Complexity and Change

    Requirement IA.L2-3.5.7 (CMMC Level 2 (L2 Baseline)): Enforce a minimum password complexity and change requirements when passwords are used as authentication.

  • IA.L2-3.5.8 - Password Reuse Prohibition

    Requirement IA.L2-3.5.8 (CMMC Level 2 (L2 Baseline)): Prohibit password reuse for a specified number of generations.

  • IA.L2-3.5.9 - Temporary Password Management

    Requirement IA.L2-3.5.9 (CMMC Level 2 (L2 Baseline)): Allow temporary password use with an immediate change requirement.

  • IA.L2-3.5.10 - Cryptographic Password Protection

    Requirement IA.L2-3.5.10 (CMMC Level 2 (L2 Baseline)): Store and transmit only cryptographically-protected passwords.

  • IA.L2-3.5.11 - Authentication Feedback Obscuring

    Requirement IA.L2-3.5.11 (CMMC Level 2 (L2 Baseline)): Obscure feedback of authentication information.

  • IA.L3-3.5.3e - MFA for Local Non-Privileged Access

    Requirement IA.L3-3.5.3e (CMMC Level 3 (L3 Enhanced)): Employ multifactor authentication (MFA) for local access to non-privileged accounts in addition to network access.

  • IA.L3-3.5.4e - Enhanced Replay Resistance

    Requirement IA.L3-3.5.4e (CMMC Level 3 (L3 Enhanced)): Employ replay-resistant authentication mechanisms and prevent the reuse of authentication factors for the defined period.

Establish an operational incident-handling capability including preparation, detection, analysis, containment, recovery, and user response. Maintain a cyber incident response team capable of operating anywhere.

  • IR.L2-3.6.1 - Incident Handling Capability

    Requirement IR.L2-3.6.1 (CMMC Level 2 (L2 Baseline)): Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.

  • IR.L2-3.6.2 - Incident Tracking and Reporting

    Requirement IR.L2-3.6.2 (CMMC Level 2 (L2 Baseline)): Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.

  • IR.L2-3.6.3 - Incident Response Testing

    Requirement IR.L2-3.6.3 (CMMC Level 2 (L2 Baseline)): Test the organizational incident response capability.

  • IR.L3-3.6.1e - Cyber Incident Response Team

    Requirement IR.L3-3.6.1e (CMMC Level 3 (L3 Enhanced)): Establish and maintain a cyber incident response team capable of investigating a cyber incident anywhere the organization operates.

Perform maintenance on organizational systems and provide controls on the tools, techniques, mechanisms, and personnel that conduct maintenance. Ensure remote maintenance uses MFA and encrypted sessions.

  • MA.L2-3.7.1 - System Maintenance

    Requirement MA.L2-3.7.1 (CMMC Level 2 (L2 Baseline)): Perform maintenance on organizational systems.

  • MA.L2-3.7.2 - Maintenance Tools and Personnel Controls

    Requirement MA.L2-3.7.2 (CMMC Level 2 (L2 Baseline)): Provide controls on the tools, techniques, mechanisms, and personnel that conduct system maintenance.

  • MA.L2-3.7.3 - Equipment Sanitization for Maintenance

    Requirement MA.L2-3.7.3 (CMMC Level 2 (L2 Baseline)): Ensure equipment removed for maintenance is sanitized.

  • MA.L2-3.7.4 - Media Check Before Maintenance Use

    Requirement MA.L2-3.7.4 (CMMC Level 2 (L2 Baseline)): Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.

  • MA.L2-3.7.5 - Multifactor Authentication for Remote Maintenance

    Requirement MA.L2-3.7.5 (CMMC Level 2 (L2 Baseline)): Require MFA for remote maintenance sessions and terminate such connections when no longer in use.

  • MA.L2-3.7.6 - Maintenance Personnel Supervision

    Requirement MA.L2-3.7.6 (CMMC Level 2 (L2 Baseline)): Supervise the maintenance activities of maintenance personnel without required access authorization.

Protect system media containing CUI — both paper and digital. Limit access, sanitize or destroy before disposal, mark, and control transport. Encrypt CUI during transmission and protect backups.

  • MP.L2-3.8.1 - Media Physical Protection and Storage

    Requirement MP.L2-3.8.1 (CMMC Level 2 (L2 Baseline)): Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.

  • MP.L2-3.8.2 - Media Access Control

    Requirement MP.L2-3.8.2 (CMMC Level 2 (L2 Baseline)): Limit access to CUI on system media to authorized users.

  • MP.L2-3.8.3 - Media Sanitization Before Disposal

    Requirement MP.L2-3.8.3 (CMMC Level 2 (L2 Baseline)): Sanitize or destroy system media before disposal or reuse.

  • MP.L2-3.8.4 - Media Marking

    Requirement MP.L2-3.8.4 (CMMC Level 2 (L2 Baseline)): Mark media with necessary CUI markings and distribution limitations.

  • MP.L2-3.8.5 - Media Transport Control

    Requirement MP.L2-3.8.5 (CMMC Level 2 (L2 Baseline)): Control access to media containing CUI and maintain accountability for media during transport.

  • MP.L2-3.8.6 - Cryptographic Protection During Transmission

    Requirement MP.L2-3.8.6 (CMMC Level 2 (L2 Baseline)): Implement cryptographic mechanisms to protect CUI during transmission unless otherwise protected by alternative physical safeguards.

  • MP.L2-3.8.7 - Removable Media Control

    Requirement MP.L2-3.8.7 (CMMC Level 2 (L2 Baseline)): Control the use of removable media on system components.

  • MP.L2-3.8.8 - Identifiable Owner Requirement for Portable Storage

    Requirement MP.L2-3.8.8 (CMMC Level 2 (L2 Baseline)): Prohibit the use of portable storage devices when such devices have no identifiable owner.

  • MP.L2-3.8.9 - CUI Backup Protection

    Requirement MP.L2-3.8.9 (CMMC Level 2 (L2 Baseline)): Protect the confidentiality of backup CUI at storage locations.

Limit physical access to systems, equipment, and operating environments to authorized individuals. Monitor facilities, escort visitors, maintain audit logs of physical access, and enforce CUI safeguards at alternate work sites.

  • PE.L2-3.10.1 - Physical Access Limitation

    Requirement PE.L2-3.10.1 (CMMC Level 2 (L2 Baseline)): Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

  • PE.L2-3.10.2 - Physical Facility Protection and Monitoring

    Requirement PE.L2-3.10.2 (CMMC Level 2 (L2 Baseline)): Protect and monitor the physical facility and support infrastructure for those systems.

  • PE.L2-3.10.3 - Visitor Escort and Monitoring

    Requirement PE.L2-3.10.3 (CMMC Level 2 (L2 Baseline)): Escort visitors and monitor visitor activity.

  • PE.L2-3.10.4 - Physical Access Audit Logs

    Requirement PE.L2-3.10.4 (CMMC Level 2 (L2 Baseline)): Maintain audit logs of physical access.

  • PE.L2-3.10.5 - Physical Access Device Management

    Requirement PE.L2-3.10.5 (CMMC Level 2 (L2 Baseline)): Control and manage physical access devices.

  • PE.L2-3.10.6 - Alternate Work Site CUI Safeguards

    Requirement PE.L2-3.10.6 (CMMC Level 2 (L2 Baseline)): Enforce safeguarding measures for CUI at alternate work sites.

Screen individuals prior to authorizing access to systems containing CUI. Ensure CUI is protected during and after personnel actions such as terminations and transfers.

  • PS.L2-3.9.1 - Personnel Screening

    Requirement PS.L2-3.9.1 (CMMC Level 2 (L2 Baseline)): Screen individuals prior to authorizing access to organizational systems containing CUI.

  • PS.L2-3.9.2 - Personnel Termination and Transfer

    Requirement PS.L2-3.9.2 (CMMC Level 2 (L2 Baseline)): Ensure that CUI is protected during and after personnel actions such as terminations and transfers.

Periodically assess risk to operations, assets, and individuals from system operation and CUI processing. Employ threat-informed risk assessments, threat intelligence, and advanced vulnerability scanning including penetration testing.

  • RA.L2-3.11.1 - Periodic Risk Assessment

    Requirement RA.L2-3.11.1 (CMMC Level 2 (L2 Baseline)): Periodically assess the risk to organizational operations, organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.

  • RA.L2-3.11.2 - Vulnerability Scanning

    Requirement RA.L2-3.11.2 (CMMC Level 2 (L2 Baseline)): Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

  • RA.L2-3.11.3 - Vulnerability Remediation

    Requirement RA.L2-3.11.3 (CMMC Level 2 (L2 Baseline)): Remediate vulnerabilities in accordance with risk assessments.

  • RA.L3-3.11.1e - Threat-Informed Risk Assessment

    Requirement RA.L3-3.11.1e (CMMC Level 3 (L3 Enhanced)): Employ threat-informed risk assessments and threat modeling that incorporates cyber threat intelligence from sources such as federal agencies, ISACs, and commercial providers.

  • RA.L3-3.11.2e - Advanced Vulnerability Analysis and Penetration Testing

    Requirement RA.L3-3.11.2e (CMMC Level 3 (L3 Enhanced)): Conduct vulnerability analysis to determine the attack surface and assess the likelihood and severity of vulnerabilities, employing advanced vulnerability scanning and penetration testing that reflect the actual threat environment.

Monitor, control, and protect communications at external and key internal boundaries. Employ deny-by-default policies, FIPS-validated cryptography, network segmentation, and comprehensive key management.

  • SC.L2-3.13.1 - Boundary Protection

    Requirement SC.L2-3.13.1 (CMMC Level 2 (L2 Baseline)): Monitor, control, and protect communications at the external boundaries and key internal boundaries of organizational systems.

  • SC.L2-3.13.2 - Security Architecture Principles

    Requirement SC.L2-3.13.2 (CMMC Level 2 (L2 Baseline)): Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.

  • SC.L2-3.13.3 - User and System Functionality Separation

    Requirement SC.L2-3.13.3 (CMMC Level 2 (L2 Baseline)): Separate user functionality from system management functionality.

  • SC.L2-3.13.4 - Shared Resource Information Leakage Prevention

    Requirement SC.L2-3.13.4 (CMMC Level 2 (L2 Baseline)): Prevent unauthorized and unintended information transfer via shared system resources.

  • SC.L2-3.13.5 - Publicly Accessible System Subnetworks

    Requirement SC.L2-3.13.5 (CMMC Level 2 (L2 Baseline)): Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

  • SC.L2-3.13.6 - Deny by Default Network Communications

    Requirement SC.L2-3.13.6 (CMMC Level 2 (L2 Baseline)): Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

  • SC.L2-3.13.7 - Split Tunneling Prevention

    Requirement SC.L2-3.13.7 (CMMC Level 2 (L2 Baseline)): Prevent remote devices from simultaneously establishing connections with the system and communicating via some other connection (split tunneling).

  • SC.L2-3.13.8 - CUI Encryption in Transit

    Requirement SC.L2-3.13.8 (CMMC Level 2 (L2 Baseline)): Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

  • SC.L2-3.13.9 - Network Connection Termination

    Requirement SC.L2-3.13.9 (CMMC Level 2 (L2 Baseline)): Terminate network connections after a defined period of inactivity.

  • SC.L2-3.13.10 - Cryptographic Key Management

    Requirement SC.L2-3.13.10 (CMMC Level 2 (L2 Baseline)): Establish and manage cryptographic keys when cryptography is employed.

  • SC.L2-3.13.11 - FIPS-Validated Cryptography

    Requirement SC.L2-3.13.11 (CMMC Level 2 (L2 Baseline)): Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

  • SC.L2-3.13.12 - Collaborative Computing Device Restrictions

    Requirement SC.L2-3.13.12 (CMMC Level 2 (L2 Baseline)): Prohibit remote activation of collaborative computing devices and provide indication of use to present users.

  • SC.L2-3.13.13 - Mobile Code Control

    Requirement SC.L2-3.13.13 (CMMC Level 2 (L2 Baseline)): Control and monitor the use of mobile code.

  • SC.L2-3.13.14 - VoIP Control and Monitoring

    Requirement SC.L2-3.13.14 (CMMC Level 2 (L2 Baseline)): Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.

  • SC.L2-3.13.15 - Session Authenticity Protection

    Requirement SC.L2-3.13.15 (CMMC Level 2 (L2 Baseline)): Protect the authenticity of communications sessions.

  • SC.L2-3.13.16 - CUI at Rest Protection

    Requirement SC.L2-3.13.16 (CMMC Level 2 (L2 Baseline)): Protect CUI at rest.

  • SC.L3-3.13.2e - Deny-by-Default Least Privilege Network Access

    Requirement SC.L3-3.13.2e (CMMC Level 3 (L3 Enhanced)): Implement a policy of deny-by-default and least-privilege access to all systems, using network-based and host-based controls, to prevent unauthorized connections and information flow.

  • SC.L3-3.13.4e - Managed Interface Deny-All Policy

    Requirement SC.L3-3.13.4e (CMMC Level 3 (L3 Enhanced)): Employ a deny-all, permit-by-exception policy on managed interfaces, enforced by boundary protection devices.

  • SC.L3-3.13.10e - Automated Cryptographic Key Management

    Requirement SC.L3-3.13.10e (CMMC Level 3 (L3 Enhanced)): Employ cryptographic key establishment procedures and key management practices that include all key life-cycle phases and automation for critical systems.

Identify, report, and correct system flaws. Protect against malicious code. Monitor systems and communications for attacks. Use threat intelligence, integrity verification, and advanced threat detection including deception techniques.

  • SI.L2-3.14.1 - Flaw Remediation

    Requirement SI.L2-3.14.1 (CMMC Level 2 (L2 Baseline)): Identify, report, and correct information and system flaws in a timely manner.

  • SI.L2-3.14.2 - Malicious Code Protection

    Requirement SI.L2-3.14.2 (CMMC Level 2 (L2 Baseline)): Provide protection from malicious code at appropriate locations within organizational systems.

  • SI.L2-3.14.3 - Security Alert Monitoring

    Requirement SI.L2-3.14.3 (CMMC Level 2 (L2 Baseline)): Monitor system security alerts and advisories and take appropriate actions in response.

  • SI.L2-3.14.4 - Malware Definition Updates

    Requirement SI.L2-3.14.4 (CMMC Level 2 (L2 Baseline)): Update malicious code protection mechanisms when new releases are available.

  • SI.L2-3.14.5 - System and File Scanning

    Requirement SI.L2-3.14.5 (CMMC Level 2 (L2 Baseline)): Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

  • SI.L2-3.14.6 - System Monitoring for Attacks

    Requirement SI.L2-3.14.6 (CMMC Level 2 (L2 Baseline)): Monitor organizational systems, including the communications at the external boundaries and key internal boundaries of those systems, to detect attacks and indicators of potential attacks.

  • SI.L2-3.14.7 - Unauthorized Use Identification

    Requirement SI.L2-3.14.7 (CMMC Level 2 (L2 Baseline)): Identify unauthorized use of organizational systems.

  • SI.L3-3.14.1e - Threat Indicator Integration

    Requirement SI.L3-3.14.1e (CMMC Level 3 (L3 Enhanced)): Use threat indicator information relevant to the information and systems being protected, including systems containing CUI, and obtained from external organizations.

  • SI.L3-3.14.3e - Software Integrity Verification

    Requirement SI.L3-3.14.3e (CMMC Level 3 (L3 Enhanced)): Verify the integrity of security-critical software using root of trust mechanisms or cryptographic signatures.

  • SI.L3-3.14.6e - Advanced Threat Detection with Deception

    Requirement SI.L3-3.14.6e (CMMC Level 3 (L3 Enhanced)): Implement an advanced threat detection capability that includes threat deception techniques (e.g., honey pots, decoys) and adversary-driven hunting based on threat intelligence to detect advanced and sophisticated cyber threats.

Establish a risk-based supply chain risk management program. Assess third-party components, ensure traceability, employ anti-tamper controls, and address nation-state threats targeting the supply chain.

  • SR.L2-3.17.1 - Supply Chain Risk Management Program

    Requirement SR.L2-3.17.1 (CMMC Level 2 (L2 Baseline)): Establish a supply chain risk management program to detect, respond to, and recover from supply chain compromises.

  • SR.L2-3.17.2 - Third-Party Component Risk Assessment

    Requirement SR.L2-3.17.2 (CMMC Level 2 (L2 Baseline)): Assess the risk associated with the use of third-party components prior to purchase and integration into the organization's systems.

  • SR.L2-3.17.3 - OEM and Supplier Security Assessment

    Requirement SR.L2-3.17.3 (CMMC Level 2 (L2 Baseline)): Use original equipment manufacturer (OEM)-qualified suppliers and assess the cyber security practices of suppliers using established standards.

  • SR.L3-3.17.1e - Supply Chain Weakness Remediation Process

    Requirement SR.L3-3.17.1e (CMMC Level 3 (L3 Enhanced)): Establish a process to address weaknesses or deficiencies in supply chain elements identified during independent third-party assessments of such elements.

  • SR.L3-3.17.2e - ICT Supply Chain Risk Assessment

    Requirement SR.L3-3.17.2e (CMMC Level 3 (L3 Enhanced)): Assess the risk of using existing or new ICT products, services, and outsourced IT/OT operations, with emphasis on provenance, integrity, and authenticity of the ICT supply chain.

  • SR.L3-3.17.3e - Component Traceability

    Requirement SR.L3-3.17.3e (CMMC Level 3 (L3 Enhanced)): Develop and implement a process to obtain and maintain traceability of critical components throughout the supply chain lifecycle.

  • SR.L3-3.17.4e - Nation-State Supply Chain Threat Program

    Requirement SR.L3-3.17.4e (CMMC Level 3 (L3 Enhanced)): Employ threat awareness programs and processes to detect and respond to threats from nation-state adversaries targeting the supply chain.

  • SR.L3-3.17.5e - Anti-Tamper Technology

    Requirement SR.L3-3.17.5e (CMMC Level 3 (L3 Enhanced)): Employ anti-tamper technologies and techniques to prevent the introduction of fraudulent or counterfeit components and detect tampering during delivery, handling, and use.