This course is designed for Certified CMMC Professionals (CCP) who are interested in becoming Certified CMMC Assessors (CCA). A Certified CMMC Assessor (CCA) applies a rigorous Assessment Process to ensure the relevant security controls have been effectively implemented and that there is evidence that these controls can be sustained. This course covers identifying the scope of an Assessment, assessing the CMMC Level 2 practices, and using an established process and workflow to enable efficiencies during an Assessment.
Learning Objectives
In this course, you will apply the CMMC Assessment Process to validate the performance of cybersecurity practices in the 14 domains derived from NIST SP 800-171, students will:
- Protect CUI with the CMMC program.
- Establish the key elements of your responsibilities as a professional CMMC Assessor.
- Work through an Assessment.
- Validate the context and scope of a Level 2 CMMC Assessment.
- Assess the practices in the Access Control (AC) domain.
- Assess the practices in the Awareness and Training (AT) domain.
- Assess the practices in the Audit and Accountability (AU) domain.
- Assess the practices in the Security Assessment (CA) domain.
- Assess the practices in the Configuration Management (CM) domain.
- Assess the practices in the Identification and Authentication (IA) domain.
- Assess the practices in the Maintenance (MA) domain.
- Assess the practices in the Media Protection (MP) domain.
- Assess the practices in the Personnel Security (PS) domain.
- Assess the practices in the Physical Protection (PE) domain.
- Assess the practices in the Risk Assessment (RA) domain.
- Assess the practices in the System and Communications Protection (SC) domain.
- Assess the practices in the System and Information Integrity (SI) domain.
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Competency Areas
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.