Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 37 Topic 4 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 37 Topic 4 Discussion

CMMC-CCA Exam Topic 4 Question 37 Discussion:
Question #: 37
Topic #: 4

You are the Lead Assessor for a CMMC assessment of an OSC that has previously obtained ISO 27001 certification for its information security management system. During the initial discussions, the OSC requests that you consider their ISO 27001 certification and grant them credit toward their CMMC certification. They believe there is a significant overlap between CMMC and ISO 27001. What should your response to the OSC be?


A.

Defer the decision on non-duplication credit until the DoD publishes official non-duplication policies.


B.

Verify the validity and authenticity of the OSC’s ISO 27001 certification against the requirements outlined in the CMMC Assessment Process (CAP) before considering granting any non-duplication credit.


C.

Inform the OSC that alternative cybersecurity certifications like ISO 27001 do not automatically bestow any status or credit towards CMMC certification.


D.

Grant the OSC credit towards their CMMC certification based on their ISO 27001 certification, as both standards cover similar cybersecurity requirements.


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.