A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?
Which regulation allows for whistleblowers to sue on behalf of the federal government?
Within the CMMC Ecosystem which organization ultimately will manage and oversee the training, testing, authorization, and certification of candidate assessors and instructors?
A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?
Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?
Who makes the final determination of the assessment method used for each practice?
For a CMMC Level 2 certification, which organization maintains a non-disclosure agreement with the OSC?
An assessor is in Phase 3 of the CMMC Assessment Process. The assessor has delivered the final findings, submitted the assessment results package, and provided feedback to the C3PAO and CMMC-AB. What must the assessor still do?
When are contractors required to achieve a CMMC certificate at the Level specified in the solicitation?
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could: