CMMC II Assessment

All 110 practices across the 14 NIST SP 800-171 domains.

Your Information

Your information is kept private and used only to send your results.
0 of 110 answered 0%

Access Control

(3.1.1) Is system access limited to authorized users processes and devices?
High impact
(3.1.2) Is access limited to the transactions and functions authorized users are permitted to execute?
High impact
(3.1.3) Is the flow of CUI controlled in accordance with approved authorizations?
(3.1.4) Are the duties of individuals separated to reduce the risk of malevolent activity without collusion?
(3.1.5) Is the principle of least privilege enforced including for privileged accounts and security functions?
High impact
(3.1.6) Are non-privileged accounts or roles used when accessing nonsecurity functions?
(3.1.7) Are non-privileged users prevented from executing privileged functions with execution captured in audit logs?
(3.1.8) Are unsuccessful logon attempts limited?
(3.1.9) Are privacy and security notices provided consistent with applicable CUI rules?
(3.1.10) Is a session lock with a pattern-hiding display used after a period of inactivity?
(3.1.11) Are user sessions terminated automatically after a defined condition?
(3.1.12) Are remote access sessions monitored and controlled?
High impact
(3.1.13) Are cryptographic mechanisms used to protect the confidentiality of remote access sessions?
High impact
(3.1.14) Is remote access routed only through managed access control points?
(3.1.15) Is remote execution of privileged commands and remote access to security-relevant information authorized?
(3.1.16) Is wireless access authorized before allowing such connections?
High impact
(3.1.17) Is wireless access protected using authentication and encryption?
High impact
(3.1.18) Is the connection of mobile devices controlled?
High impact
(3.1.19) Is CUI encrypted on mobile devices and mobile computing platforms?
High impact
(3.1.20) Are connections to and use of external systems verified and controlled?
(3.1.21) Is the use of portable storage devices on external systems limited?
(3.1.22) Is CUI posted or processed on publicly accessible systems controlled?

Awareness and Training

(3.2.1) Are managers and users made aware of the security risks of their activities and applicable policies?
High impact
(3.2.2) Are personnel trained to carry out their assigned information-security duties?
High impact
(3.2.3) Is awareness training provided on recognizing and reporting potential indicators of insider threat?

Audit and Accountability

(3.3.1) Are system audit logs created and retained to enable monitoring analysis and investigation of unlawful activity?
High impact
(3.3.2) Can the actions of individual users be uniquely traced to support accountability?
High impact
(3.3.3) Are logged events reviewed and updated on a defined basis?
(3.3.4) Is an alert generated in the event of an audit logging process failure?
(3.3.5) Are audit records correlated for review analysis and reporting to support investigation and response?
High impact
(3.3.6) Is audit record reduction and report generation provided to support analysis and reporting?
(3.3.7) Are internal system clocks synchronized to generate accurate timestamps for audit records?
(3.3.8) Are audit information and audit logging tools protected from unauthorized access modification and deletion?
(3.3.9) Is management of audit logging functionality limited to a subset of privileged users?

Configuration Management

(3.4.1) Are baseline configurations and inventories of organizational systems established and maintained?
High impact
(3.4.2) Are security configuration settings for IT products established and enforced?
High impact
(3.4.3) Are changes to organizational systems tracked reviewed approved and logged?
(3.4.4) Is the security impact of changes analyzed before implementation?
(3.4.5) Are physical and logical access restrictions associated with changes defined documented and enforced?
High impact
(3.4.6) Is the principle of least functionality applied by providing only essential capabilities?
High impact
(3.4.7) Is the use of nonessential programs functions ports protocols and services restricted or disabled?
High impact
(3.4.8) Is a deny-by-exception or permit-by-exception policy applied to control software execution?
High impact
(3.4.9) Is user-installed software controlled and monitored?

Identification and Authentication

(3.5.1) Are system users processes and devices uniquely identified?
High impact
(3.5.2) Are the identities of users processes and devices authenticated before granting access?
High impact
(3.5.3) Is multifactor authentication used for local and network access to privileged accounts and network access to non-privileged accounts?
High impact
(3.5.4) Are replay-resistant authentication mechanisms employed for network access to privileged and non-privileged accounts?
(3.5.5) Is the reuse of identifiers prevented for a defined period?
(3.5.6) Are identifiers disabled after a defined period of inactivity?
(3.5.7) Is a minimum password complexity enforced when new passwords are created?
(3.5.8) Is password reuse prohibited for a specified number of generations?
(3.5.9) Is temporary password use allowed only with an immediate change to a permanent password?
(3.5.10) Are passwords stored and transmitted only in cryptographically-protected form?
High impact
(3.5.11) Is feedback of authentication information obscured during the authentication process?

Incident Response

(3.6.1) Is an operational incident-handling capability established covering preparation detection analysis containment recovery and user response?
High impact
(3.6.2) Are incidents tracked documented and reported to designated internal and external officials?
High impact
(3.6.3) Is the organizational incident response capability tested on a defined basis?

Maintenance

(3.7.1) Is maintenance performed on organizational systems on a controlled basis?
High impact
(3.7.2) Are controls provided on the tools techniques mechanisms and personnel used to conduct system maintenance?
High impact
(3.7.3) Is equipment removed for off-site maintenance sanitized of any CUI?
(3.7.4) Is media containing diagnostic and test programs checked for malicious code before use?
High impact
(3.7.5) Is multifactor authentication required for nonlocal maintenance sessions and are those sessions terminated when complete?
High impact
(3.7.6) Are maintenance activities of personnel without required access authorization supervised?

Media Protection

(3.8.1) Is system media containing CUI both paper and digital physically controlled and securely stored?
High impact
(3.8.2) Is access to CUI on system media limited to authorized users?
High impact
(3.8.3) Is system media containing CUI sanitized or destroyed before disposal or reuse?
High impact
(3.8.4) Is media marked with necessary CUI markings and distribution limitations?
(3.8.5) Is access to CUI media controlled and accountability maintained during transport outside controlled areas?
(3.8.6) Are cryptographic mechanisms used to protect the confidentiality of CUI stored on digital media during transport?
(3.8.7) Is the use of removable media on system components controlled?
High impact
(3.8.8) Is the use of portable storage devices prohibited when such devices have no identifiable owner?
High impact
(3.8.9) Is the confidentiality of backup CUI protected at storage locations?

Personnel Security

(3.9.1) Are individuals screened before authorizing access to systems containing CUI?
High impact
(3.9.2) Are CUI and systems protected during and after personnel actions such as terminations and transfers?
High impact

Physical Protection

(3.10.1) Is physical access to systems equipment and operating environments limited to authorized individuals?
High impact
(3.10.2) Is the physical facility and supporting infrastructure protected and monitored?
High impact
(3.10.3) Are visitors escorted and their activity monitored?
(3.10.4) Are audit logs of physical access maintained?
(3.10.5) Are physical access devices controlled and managed?
(3.10.6) Are safeguarding measures for CUI enforced at alternate work sites?

Risk Assessment

(3.11.1) Is risk to operations assets and individuals periodically assessed from processing storing and transmitting CUI?
High impact
(3.11.2) Are systems and applications scanned for vulnerabilities periodically and when new vulnerabilities are identified?
High impact
(3.11.3) Are vulnerabilities remediated in accordance with risk assessments?

Security Assessment

(3.12.1) Are security controls periodically assessed to determine their effectiveness?
High impact
(3.12.2) Are plans of action developed and implemented to correct deficiencies and reduce vulnerabilities?
High impact
(3.12.3) Are security controls monitored on an ongoing basis to ensure continued effectiveness?
High impact
(3.12.4) Is a system security plan developed documented and periodically updated?

System and Communications Protection

(3.13.1) Are communications monitored controlled and protected at external boundaries and key internal boundaries?
High impact
(3.13.2) Are architectural designs and systems engineering principles applied that promote effective information security?
High impact
(3.13.3) Is user functionality separated from system management functionality?
(3.13.4) Is unauthorized and unintended information transfer via shared system resources prevented?
(3.13.5) Are publicly accessible system components placed in subnetworks separated from internal networks?
High impact
(3.13.6) Is network traffic denied by default and allowed by exception?
High impact
(3.13.7) Are remote devices prevented from split tunneling while connected to organizational systems?
(3.13.8) Are cryptographic mechanisms used to prevent unauthorized disclosure of CUI during transmission?
High impact
(3.13.9) Are network connections terminated at the end of sessions or after a defined period of inactivity?
(3.13.10) Are cryptographic keys established and managed for cryptography employed in organizational systems?
(3.13.11) Is FIPS-validated cryptography employed to protect the confidentiality of CUI?
High impact
(3.13.12) Is remote activation of collaborative computing devices prohibited with indication of use provided to present users?
(3.13.13) Is the use of mobile code controlled and monitored?
(3.13.14) Is the use of Voice over Internet Protocol technologies controlled and monitored?
(3.13.15) Is the authenticity of communications sessions protected?
High impact
(3.13.16) Is the confidentiality of CUI protected at rest?

System and Information Integrity

(3.14.1) Are system flaws identified reported and corrected in a timely manner?
High impact
(3.14.2) Is protection from malicious code provided at designated locations within organizational systems?
High impact
(3.14.3) Are system security alerts and advisories monitored and acted upon?
High impact
(3.14.4) Are malicious code protection mechanisms updated when new releases are available?
High impact
(3.14.5) Are periodic system scans and real-time scans of files from external sources performed?
High impact
(3.14.6) Are systems and inbound and outbound traffic monitored to detect attacks and indicators of potential attacks?
High impact
(3.14.7) Is unauthorized use of organizational systems identified?
High impact
Please answer all questions. remaining.
Results will be emailed to you immediately after submission.
Powered by Blackhawk MSP