Understanding Policy Validation in CMMC AssessmentsDuring a CMMC assessment, policies must be evaluated based on:
Who has the authority to approve and enforce them
Whether they are current and implemented effectively
The validity of a policydoes not solely depend on the signatorybut rather onhow the organization assigns authority for policy creation, approval, and enforcement.
Some organizations assignauthority to a specific person, meaning anew signatory may be requiredwhen leadership changes.
Others assign authority to aposition/title(e.g., CISO, IT Director), in which casea new signature may not be requiredas long as the role remains responsible for policy enforcement.
The assessment teammust review the organization's policy management processto determine if the policy remains valid despite leadership turnover.
Key Considerations in Policy Validation:Thus,the correct answer is B, as additional research is needed to confirm whether the organization's policy is tied to the individual or the position.
A. The signatory is the authority to implement and enforce the policy, and since that person is no longer with the company, the policy is not valid.❌Incorrect. This assumes thatauthority is always tied to a person, which is not always the case. Some organizations delegate authorityto a position, not an individual.
C. The signatory does not validate or invalidate the policy. For the purpose of this assessment, ensuring that the policy is current and is being implemented by the individuals who are performing the work is sufficient.❌Incorrect. While implementation is crucial,the authority behind the policy must also be validatedper CMMC documentation requirements.
D. The authority to implement and enforce lies with the position, not the person. As long as that position's authority and responsibilities have not been removed from implementing that domain, it is still a valid policy.❌Incorrect. This assumes thatauthority is always assigned to a position, which is not universally true. More research is required to confirm this.
Why the Other Answers Are Incorrect
CMMC Assessment Process (CAP) Document– Outlines the importance of verifying the authority and enforcement of policies.
NIST SP 800-171 (3.12.1 - Security Policies and Procedures)– Requires that policies be maintained and enforced by appropriate personnel.
CMMC Official ReferencesThus,option B (More research on the company policy is needed) is the correct answer, as per official CMMC policy validation guidance.
Submit