Obligation
Assessment
11 items across the GovConCyber reference layer carry this topic.
Requirements
- Periodically Assess Risk
- Scan for Vulnerabilities
- Remediate Vulnerabilities by Risk
- Periodically Assess Security Controls
- Develop Plans of Action (POA&M)
- Continuously Monitor Controls
- Maintain a System Security Plan
- Obtain and Maintain CMMC Certification at the Required Level
- Use FedRAMP-Authorized Cloud for CUI (DoD: FedRAMP-Moderate Equivalent)
- Obtain and Maintain a FedRAMP Authorization
- Obtain and Maintain a StateRAMP Authorization