Comprehensive and Detailed in Depth Explanation:
The CMMC Assessment Process (CAP) v1.0 specifies that certain practice objectives, particularly in domains like Media Protection (MP), Personnel Security (PS), and Physical Protection (PE), require on-premises observation due to their physical nature (e.g., MP.L2-3.8.7, PE.L2-3.10.2). As the designated on-site assessor, your focus is on validating these objectives in person. The CAP identifies 15 practice objectives requiring on-site verification, emphasizing critical areas where CUI is processed, stored, or protected.
Option A (DoD-approved collaboration tools) and Option C (Virtual Assessment Evidence Preparation Template) pertain to virtual assessment logistics, not your on-site responsibilities. Option B (limitations of on-premises assessments) is relevant as it addresses potential constraints you must navigate for MP, PS, and PE domains. However, Option D (non-critical areas of OSC facilities) is irrelevant because your on-site work targets only areas within the assessment scope where CUI-related practices are implemented, not non-critical areas unrelated to CMMC compliance. Thus, Option D is the correct answer.
Reference Extract:
CMMC Assessment Process (CAP) v1.0, Section 3.5.2:“Fifteen practice objectives across MP, PS, and PE domains require on-premises observation to validate implementation.”
CMMC AG Level 2, Section 3.10:“Physical protection practices must be assessed in areas where CUI is present, not non-critical facility zones.”Resources:https://cyberab.org/Portals/0/Documents/Process-Documents/CMMC-Assessment-Process-CAP-v1.0.pdf ;https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Submit