CMMC II Assessment
All 110 practices across the 14 NIST SP 800-171 domains.
Your Information
Full Name *
Company *
Email *
Phone *
Your information is kept private and used only to send your results.
0 of 110 answered
0%
Access Control
(3.1.1) Is system access limited to authorized users processes and devices?
High impact
Yes
No
(3.1.2) Is access limited to the transactions and functions authorized users are permitted to execute?
High impact
Yes
No
(3.1.3) Is the flow of CUI controlled in accordance with approved authorizations?
Yes
No
(3.1.4) Are the duties of individuals separated to reduce the risk of malevolent activity without collusion?
Yes
No
(3.1.5) Is the principle of least privilege enforced including for privileged accounts and security functions?
High impact
Yes
No
(3.1.6) Are non-privileged accounts or roles used when accessing nonsecurity functions?
Yes
No
(3.1.7) Are non-privileged users prevented from executing privileged functions with execution captured in audit logs?
Yes
No
(3.1.8) Are unsuccessful logon attempts limited?
Yes
No
(3.1.9) Are privacy and security notices provided consistent with applicable CUI rules?
Yes
No
(3.1.10) Is a session lock with a pattern-hiding display used after a period of inactivity?
Yes
No
(3.1.11) Are user sessions terminated automatically after a defined condition?
Yes
No
(3.1.12) Are remote access sessions monitored and controlled?
High impact
Yes
No
(3.1.13) Are cryptographic mechanisms used to protect the confidentiality of remote access sessions?
High impact
Yes
No
(3.1.14) Is remote access routed only through managed access control points?
Yes
No
(3.1.15) Is remote execution of privileged commands and remote access to security-relevant information authorized?
Yes
No
(3.1.16) Is wireless access authorized before allowing such connections?
High impact
Yes
No
(3.1.17) Is wireless access protected using authentication and encryption?
High impact
Yes
No
(3.1.18) Is the connection of mobile devices controlled?
High impact
Yes
No
(3.1.19) Is CUI encrypted on mobile devices and mobile computing platforms?
High impact
Yes
No
(3.1.20) Are connections to and use of external systems verified and controlled?
Yes
No
(3.1.21) Is the use of portable storage devices on external systems limited?
Yes
No
(3.1.22) Is CUI posted or processed on publicly accessible systems controlled?
Yes
No
Awareness and Training
(3.2.1) Are managers and users made aware of the security risks of their activities and applicable policies?
High impact
Yes
No
(3.2.2) Are personnel trained to carry out their assigned information-security duties?
High impact
Yes
No
(3.2.3) Is awareness training provided on recognizing and reporting potential indicators of insider threat?
Yes
No
Audit and Accountability
(3.3.1) Are system audit logs created and retained to enable monitoring analysis and investigation of unlawful activity?
High impact
Yes
No
(3.3.2) Can the actions of individual users be uniquely traced to support accountability?
High impact
Yes
No
(3.3.3) Are logged events reviewed and updated on a defined basis?
Yes
No
(3.3.4) Is an alert generated in the event of an audit logging process failure?
Yes
No
(3.3.5) Are audit records correlated for review analysis and reporting to support investigation and response?
High impact
Yes
No
(3.3.6) Is audit record reduction and report generation provided to support analysis and reporting?
Yes
No
(3.3.7) Are internal system clocks synchronized to generate accurate timestamps for audit records?
Yes
No
(3.3.8) Are audit information and audit logging tools protected from unauthorized access modification and deletion?
Yes
No
(3.3.9) Is management of audit logging functionality limited to a subset of privileged users?
Yes
No
Configuration Management
(3.4.1) Are baseline configurations and inventories of organizational systems established and maintained?
High impact
Yes
No
(3.4.2) Are security configuration settings for IT products established and enforced?
High impact
Yes
No
(3.4.3) Are changes to organizational systems tracked reviewed approved and logged?
Yes
No
(3.4.4) Is the security impact of changes analyzed before implementation?
Yes
No
(3.4.5) Are physical and logical access restrictions associated with changes defined documented and enforced?
High impact
Yes
No
(3.4.6) Is the principle of least functionality applied by providing only essential capabilities?
High impact
Yes
No
(3.4.7) Is the use of nonessential programs functions ports protocols and services restricted or disabled?
High impact
Yes
No
(3.4.8) Is a deny-by-exception or permit-by-exception policy applied to control software execution?
High impact
Yes
No
(3.4.9) Is user-installed software controlled and monitored?
Yes
No
Identification and Authentication
(3.5.1) Are system users processes and devices uniquely identified?
High impact
Yes
No
(3.5.2) Are the identities of users processes and devices authenticated before granting access?
High impact
Yes
No
(3.5.3) Is multifactor authentication used for local and network access to privileged accounts and network access to non-privileged accounts?
High impact
Yes
No
(3.5.4) Are replay-resistant authentication mechanisms employed for network access to privileged and non-privileged accounts?
Yes
No
(3.5.5) Is the reuse of identifiers prevented for a defined period?
Yes
No
(3.5.6) Are identifiers disabled after a defined period of inactivity?
Yes
No
(3.5.7) Is a minimum password complexity enforced when new passwords are created?
Yes
No
(3.5.8) Is password reuse prohibited for a specified number of generations?
Yes
No
(3.5.9) Is temporary password use allowed only with an immediate change to a permanent password?
Yes
No
(3.5.10) Are passwords stored and transmitted only in cryptographically-protected form?
High impact
Yes
No
(3.5.11) Is feedback of authentication information obscured during the authentication process?
Yes
No
Incident Response
(3.6.1) Is an operational incident-handling capability established covering preparation detection analysis containment recovery and user response?
High impact
Yes
No
(3.6.2) Are incidents tracked documented and reported to designated internal and external officials?
High impact
Yes
No
(3.6.3) Is the organizational incident response capability tested on a defined basis?
Yes
No
Maintenance
(3.7.1) Is maintenance performed on organizational systems on a controlled basis?
High impact
Yes
No
(3.7.2) Are controls provided on the tools techniques mechanisms and personnel used to conduct system maintenance?
High impact
Yes
No
(3.7.3) Is equipment removed for off-site maintenance sanitized of any CUI?
Yes
No
(3.7.4) Is media containing diagnostic and test programs checked for malicious code before use?
High impact
Yes
No
(3.7.5) Is multifactor authentication required for nonlocal maintenance sessions and are those sessions terminated when complete?
High impact
Yes
No
(3.7.6) Are maintenance activities of personnel without required access authorization supervised?
Yes
No
Media Protection
(3.8.1) Is system media containing CUI both paper and digital physically controlled and securely stored?
High impact
Yes
No
(3.8.2) Is access to CUI on system media limited to authorized users?
High impact
Yes
No
(3.8.3) Is system media containing CUI sanitized or destroyed before disposal or reuse?
High impact
Yes
No
(3.8.4) Is media marked with necessary CUI markings and distribution limitations?
Yes
No
(3.8.5) Is access to CUI media controlled and accountability maintained during transport outside controlled areas?
Yes
No
(3.8.6) Are cryptographic mechanisms used to protect the confidentiality of CUI stored on digital media during transport?
Yes
No
(3.8.7) Is the use of removable media on system components controlled?
High impact
Yes
No
(3.8.8) Is the use of portable storage devices prohibited when such devices have no identifiable owner?
High impact
Yes
No
(3.8.9) Is the confidentiality of backup CUI protected at storage locations?
Yes
No
Personnel Security
(3.9.1) Are individuals screened before authorizing access to systems containing CUI?
High impact
Yes
No
(3.9.2) Are CUI and systems protected during and after personnel actions such as terminations and transfers?
High impact
Yes
No
Physical Protection
(3.10.1) Is physical access to systems equipment and operating environments limited to authorized individuals?
High impact
Yes
No
(3.10.2) Is the physical facility and supporting infrastructure protected and monitored?
High impact
Yes
No
(3.10.3) Are visitors escorted and their activity monitored?
Yes
No
(3.10.4) Are audit logs of physical access maintained?
Yes
No
(3.10.5) Are physical access devices controlled and managed?
Yes
No
(3.10.6) Are safeguarding measures for CUI enforced at alternate work sites?
Yes
No
Risk Assessment
(3.11.1) Is risk to operations assets and individuals periodically assessed from processing storing and transmitting CUI?
High impact
Yes
No
(3.11.2) Are systems and applications scanned for vulnerabilities periodically and when new vulnerabilities are identified?
High impact
Yes
No
(3.11.3) Are vulnerabilities remediated in accordance with risk assessments?
Yes
No
Security Assessment
(3.12.1) Are security controls periodically assessed to determine their effectiveness?
High impact
Yes
No
(3.12.2) Are plans of action developed and implemented to correct deficiencies and reduce vulnerabilities?
High impact
Yes
No
(3.12.3) Are security controls monitored on an ongoing basis to ensure continued effectiveness?
High impact
Yes
No
(3.12.4) Is a system security plan developed documented and periodically updated?
Yes
No
System and Communications Protection
(3.13.1) Are communications monitored controlled and protected at external boundaries and key internal boundaries?
High impact
Yes
No
(3.13.2) Are architectural designs and systems engineering principles applied that promote effective information security?
High impact
Yes
No
(3.13.3) Is user functionality separated from system management functionality?
Yes
No
(3.13.4) Is unauthorized and unintended information transfer via shared system resources prevented?
Yes
No
(3.13.5) Are publicly accessible system components placed in subnetworks separated from internal networks?
High impact
Yes
No
(3.13.6) Is network traffic denied by default and allowed by exception?
High impact
Yes
No
(3.13.7) Are remote devices prevented from split tunneling while connected to organizational systems?
Yes
No
(3.13.8) Are cryptographic mechanisms used to prevent unauthorized disclosure of CUI during transmission?
High impact
Yes
No
(3.13.9) Are network connections terminated at the end of sessions or after a defined period of inactivity?
Yes
No
(3.13.10) Are cryptographic keys established and managed for cryptography employed in organizational systems?
Yes
No
(3.13.11) Is FIPS-validated cryptography employed to protect the confidentiality of CUI?
High impact
Yes
No
(3.13.12) Is remote activation of collaborative computing devices prohibited with indication of use provided to present users?
Yes
No
(3.13.13) Is the use of mobile code controlled and monitored?
Yes
No
(3.13.14) Is the use of Voice over Internet Protocol technologies controlled and monitored?
Yes
No
(3.13.15) Is the authenticity of communications sessions protected?
High impact
Yes
No
(3.13.16) Is the confidentiality of CUI protected at rest?
Yes
No
System and Information Integrity
(3.14.1) Are system flaws identified reported and corrected in a timely manner?
High impact
Yes
No
(3.14.2) Is protection from malicious code provided at designated locations within organizational systems?
High impact
Yes
No
(3.14.3) Are system security alerts and advisories monitored and acted upon?
High impact
Yes
No
(3.14.4) Are malicious code protection mechanisms updated when new releases are available?
High impact
Yes
No
(3.14.5) Are periodic system scans and real-time scans of files from external sources performed?
High impact
Yes
No
(3.14.6) Are systems and inbound and outbound traffic monitored to detect attacks and indicators of potential attacks?
High impact
Yes
No
(3.14.7) Is unauthorized use of organizational systems identified?
High impact
Yes
No
Please answer all questions.
remaining.
Get My Results
Results will be emailed to you immediately after submission.
Powered by Blackhawk MSP