Which term describes "the protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to. or modification of information"?
What is the MOST common purpose of assessment procedures?
Which entity requires that organizations handling FCI or CUI be assessed to determine a required Level of cybersecurity maturity?
When assessing SI.L1-3.14.2: Provide protection from malicious code at appropriate locations within organizational information systems, evidence shows that all of the OSC's workstations and servers have antivirus software installed for malicious code protection. A centralized console for the antivirus software management is in place and records show that all devices have received the most updated antivirus patterns. What is the BEST determination that the Lead Assessor should reach regarding the evidence?
What is the MINIMUM required marking for a document containing CUI?
While conducting a CMMC Level 2 Assessment, a CCP is reviewing an OSC's personnel security process. They have a policy that describes screening individuals prior to authorizing access to CUI, but it does not mention what organizations should be looking for in an individual. There is no link to a process or procedural document. What should the OSC evaluate when screening individuals prior to accessing CUI?
Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?
The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?
A Lead Assessor is preparing to conduct a Readiness Review during Phase 1 of the Assessment Process. How much evidence MUST be gathered for each practice?
Which MINIMUM Level of certification must a contractor successfully achieve to receive a contract award requiring the handling of CUI?