During a CMMC assessment, you, as a CCA, are interviewing a key OSC employee with information security responsibilities about the access control procedures. As the interview progresses, you realize that the initial information provided in the System Security Plan (SSP) doesn’t fully align with the employee’s explanation. Based on the scenario and your role as a CCA, what is not one of your responsibilities as an assessment team member?
Submit