Step 1: Understanding AC.L1-3.1.22
AC.L1-3.1.22states:"Control information posted or processed on publicly accessible systems."
This control requires organizations toensure that FCI (Federal Contract Information) is not publicly postedor made accessible in an uncontrolled manner.
FCI must beprotected from unauthorized disclosure, even if it is not classified or CUI.
[Reference:, NIST SP 800-171, Requirement 3.1.22, CMMC Level 1 Practice AC.L1-3.1.22, Step 2: Why Safeguarding FCI is Critical in a Press Release, If the company releases apress statementthat includesFCI, it must ensure that the information is not inadvertently exposing sensitive contract-related data., FCI includesinformation provided by or generated for theDoD under a contractthat isnot intended for public release., Organizations mustimplement controlsto prevent unintentional exposure., Step 3: Why Other Answer Choices Are Incorrect, A. That the information is correct (Incorrect):, While accuracy is important,CMMC requirements focus on protecting sensitive information, not just ensuring correctness., B. That the CEO approved the message (Incorrect):, CEO approval does not satisfy CMMC compliance, as it does not address safeguarding FCI., D. That so long as the information is only FCI, it can be released (Incorrect):, FCI must be protected and cannot be publicly disclosed unless specifically authorizedby the DoD., Final Confirmation of Correct Answer:, The company must safeguard FCI and ensure that no unauthorized disclosures occur in a public press release., Thus, the correct answer is:C. That the company has to safeguard the release of FCI, , ]
Submit