Cloud Shared Responsibility Mapper
Framework

CMMC 2.0: the clauses behind the split

CMMC 2.0. Pick Level 1 or Level 2: Level 1 is the 17 practices of FAR 52.204-21 and the page shows only those; Level 2 adds the rest of NIST SP 800-171. The CMMC assessment guide is named, not quoted. A Level 1 practice is also a Level 2 practice.

Shown when ticked. The framework on the compliance library.

Control areas it anchors

14
AreaClause
Governance and policyCMMC CA.L2-3.12.4
Identity and accessCMMC AC.L2-3.1.1 · CMMC IA.L2-3.5.3
Data classification and handlingCMMC AC.L2-3.1.3
Encryption and keysCMMC SC.L2-3.13.10 · CMMC SC.L2-3.13.16
Network securityCMMC SC.L2-3.13.1
Logging and monitoringCMMC AU.L2-3.3.1
Vulnerability and patch managementCMMC SI.L2-3.14.1
Configuration and hardeningCMMC CM.L2-3.4.2
Application securityCMMC SC.L2-3.13.2
Incident responseCMMC IR.L2-3.6.2
Business continuity and backupCMMC MP.L2-3.8.9
Physical and environmentalCMMC PE.L2-3.10.1
Supplier and subserviceCMMC AC.L2-3.1.20
AI use and data retentionCMMC AC.L2-3.1.22

Every clause cited, quoted

16 of the 110 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

CMMC AC.L2-3.1.1 Authorized Access Control Level 1 and 2

Restrict system access so only identified, authorized users, the processes running on their behalf, and approved devices including other connected systems can connect.

What an assessor asks to see:
  • Account inventory listing authorized users, service/process accounts and approved devices
  • Account provisioning and approval records showing authorization before access
  • System configuration showing device and system-to-system connection allow lists
  • Periodic account recertification results
Where it usually falls short:
  • Service and machine accounts never authorized or reviewed
  • Device-level access unrestricted while user access is controlled
  • Stale accounts retained after staff depart
Source: CMMC 2.0
CMMC AC.L2-3.1.3 Control CUI Flow Level 2

Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.

What an assessor asks to see:
  • Documented CUI flow authorizations and approved flow paths
  • Firewall, proxy, DLP or gateway rules enforcing those flows
  • Data flow diagrams identifying CUI sources, stores and destinations
  • Records of blocked or exception-approved transfers
Where it usually falls short:
  • CUI flows documented but not technically enforced
  • Egress to cloud and email paths unmonitored for CUI
  • No defined authorization for flows to external partners
Source: CMMC 2.0
CMMC AC.L2-3.1.20 External Connections Level 1 and 2

Verify, then control or limit, connections to and use of external systems that are outside organizational control.

What an assessor asks to see:
  • Inventory of approved external systems and connection terms
  • Agreements or terms governing external system use
  • Technical controls limiting external system connections
Where it usually falls short:
  • External cloud services used without review
  • Connections permitted with no verification of the external party
  • No limit on what CUI may be processed externally
Source: CMMC 2.0
CMMC AC.L2-3.1.22 Control Public Information Level 1 and 2

Control CUI that is posted to or processed on publicly accessible systems so CUI is not released to the public.

What an assessor asks to see:
  • Review and approval process for content published publicly
  • Designated reviewer authorizations and review records
  • Evidence of periodic scanning of public sites for CUI
Where it usually falls short:
  • Publication approval informal or undocumented
  • No periodic check of already published content
  • Public facing systems not identified as in scope
Source: CMMC 2.0
CMMC AU.L2-3.3.1 System Auditing Level 2

Generate and retain system audit logs in sufficient scope and detail to support monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity.

What an assessor asks to see:
  • Defined auditable event list and rationale for its scope
  • Logging configuration on in scope systems
  • Retention settings and evidence logs are retained for the defined period
  • Sample audit records showing captured content
Where it usually falls short:
  • Logging enabled with default event sets never assessed for sufficiency
  • Retention shorter than investigation needs
  • In scope systems missing from logging coverage
Source: CMMC 2.0
CMMC CA.L2-3.12.4 System Security Plan Level 2

Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.

What an assessor asks to see:
  • Current system security plan covering boundary, environment, implementation and interconnections
  • Version history showing periodic update
  • Approval record for the current version
Where it usually falls short:
  • Plan describes intent rather than actual implementation
  • Boundary and interconnections omitted or stale
  • No defined update trigger or cadence
Source: CMMC 2.0
CMMC CM.L2-3.4.2 Security Configuration Enforcement Level 2

Define security configuration settings for the IT products used in the system and enforce those settings in operation.

What an assessor asks to see:
  • Documented security configuration settings or hardening standards
  • Evidence of enforcement, for example policy objects or configuration management tooling
  • Compliance scan results against the defined settings
Where it usually falls short:
  • Standards documented but drift never measured
  • Settings applied at build with no ongoing enforcement
  • Products in use with no defined hardening standard
Source: CMMC 2.0
CMMC IA.L2-3.5.3 Multifactor Authentication Level 2

Require more than one authentication factor for privileged account access both locally and across the network, and for non privileged account access across the network.

What an assessor asks to see:
  • Multifactor configuration showing coverage of the required access cases
  • Enrolment records for privileged account holders
  • Evidence of enforcement for network access by non privileged users
Where it usually falls short:
  • Multifactor applied to remote access only, missing local privileged access
  • Exemptions granted for service or legacy accounts without compensating control
  • Second factor is another knowledge factor
Source: CMMC 2.0
CMMC IR.L2-3.6.2 Incident Reporting Level 2

Track, document and report incidents to the designated internal officials and to external authorities where required.

What an assessor asks to see:
  • Incident register with tracking and documentation per incident
  • Defined internal officials and external reporting obligations
  • Evidence of reports made within required timeframes
Where it usually falls short:
  • External reporting obligations unidentified
  • Incidents handled informally and never documented
  • Reporting timeframes undefined so notifications are late
Source: CMMC 2.0
CMMC MP.L2-3.8.9 Protect Backups Level 2

Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.

What an assessor asks to see:
  • Backup inventory identifying which backups contain CUI
  • Protection applied at backup storage locations, encryption or physical control
  • Access controls and records for backup storage
Where it usually falls short:
  • Production data protected while backups are not
  • Offsite and cloud backup locations unassessed
  • Backup encryption keys stored alongside the backups
Source: CMMC 2.0
CMMC PE.L2-3.10.1 Limit Physical Access Level 1 and 2

Limit physical access to systems, equipment and their operating environments to authorized individuals.

What an assessor asks to see:
  • Physical access authorization list for controlled areas
  • Access control mechanism evidence such as badge system configuration
  • Periodic review of who holds physical access
Where it usually falls short:
  • Access lists not reviewed so departed staff retain badges
  • Server and equipment areas within general office access
  • Authorization granted verbally without record
Source: CMMC 2.0
CMMC SC.L2-3.13.1 Boundary Protection Level 1 and 2

Monitor, control and protect communications at the external boundary of the system and at key internal boundaries.

What an assessor asks to see:
  • Network architecture identifying external and key internal boundaries
  • Boundary device configuration such as firewall and gateway rulesets
  • Monitoring evidence at those boundaries
Where it usually falls short:
  • External boundary protected while internal boundaries are flat
  • Boundary devices configured but traffic not monitored
  • Cloud and remote boundaries omitted from the architecture
Source: CMMC 2.0
CMMC SC.L2-3.13.2 Security Engineering Level 2

Apply architectural design, software development techniques and systems engineering principles that promote effective information security.

What an assessor asks to see:
  • Documented security architecture and design principles
  • Secure development standards applied to in house software
  • Evidence principles are applied in design reviews
Where it usually falls short:
  • Principles documented but absent from actual design decisions
  • Secure development standards not applied to acquired or outsourced code
  • No design review step in the development process
Source: CMMC 2.0
CMMC SC.L2-3.13.10 Key Management Level 2

Establish and manage the cryptographic keys used by cryptography employed in organizational systems, across their life cycle.

What an assessor asks to see:
  • Key management procedure covering generation, distribution, storage, rotation and destruction
  • Key inventory and custodian assignments
  • Evidence of key rotation and secure storage
Where it usually falls short:
  • Keys generated and then never rotated or inventoried
  • Private keys stored alongside the data they protect
  • Key custodianship undefined so departures leave keys orphaned
Source: CMMC 2.0
CMMC SC.L2-3.13.16 Data at Rest Level 2

Protect the confidentiality of CUI while it is at rest in storage.

What an assessor asks to see:
  • Inventory of locations where CUI is stored at rest
  • Encryption or equivalent protection configuration at those locations
  • Evidence of protection coverage including databases, file shares and endpoints
Where it usually falls short:
  • Endpoint encryption in place while servers and shares are unprotected
  • Storage locations for CUI never fully inventoried
  • Cloud storage protection assumed from the provider without verification
Source: CMMC 2.0
CMMC SI.L2-3.14.1 Flaw Remediation Level 1 and 2

Identify system flaws, report them, and correct them within a timely period.

What an assessor asks to see:
  • Flaw identification sources and process
  • Patch and remediation records with dates showing timeliness
  • Defined timeframes for correction by severity
Where it usually falls short:
  • Flaws identified but remediation timeframes undefined
  • Patching covers operating systems only, omitting applications and firmware
  • Reporting step absent so flaws are not tracked
Source: CMMC 2.0