Understanding the Definition of a " Practice " in CMMC 2.0
In CMMC 2.0, the term " practice " refers to specific cybersecurity activities that organizations must implement to achieve compliance with defined security objectives.
Step-by-Step Breakdown:
Definition from CMMC Documentation:
According to theCMMC Model Overview, apracticeis defined as:
" An activity or activities performed to meet defined CMMC objectives. "
This means that practices are theactions and implementations required to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
How Practices Fit into CMMC 2.0:
CMMC 2.0 Level 1 consists of17 practices, which align withFAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems).
CMMC 2.0 Level 2 consists of110 practices, aligned directly withNIST SP 800-171 Rev. 2.
Each practice has anobjectivethat must be met to demonstrate compliance.
Official CMMC 2.0 References:
TheCMMC 2.0 Model Documentationdefines practices as " the fundamental cybersecurity activities necessary to achieve security objectives. "
TheCMMC Assessment Process (CAP) Guideoutlines how assessors verify the implementation of these practices during an assessment.
TheNIST SP 800-171A Guideprovidesassessment objectivesfor each practice to ensure they are implemented effectively.
Comparison with Other Answer Choices:
A. A business transaction→ Incorrect. CMMC practices focus on cybersecurity activities, not financial or operational transactions.
B. A condition arrived at by experience or exercise→ Incorrect. While practices evolve over time, they are defined activities, not just experience-based conditions.
C. A series of changes taking place in a defined manner→ Incorrect. A practice is a set of security actions, not just a process of change.
Conclusion:
ACMMC practicerefers to specificcybersecurity activities performed to meet defined CMMC objectives. This makesOption Dthe correct answer.
Submit