Tag: Assessment

Home / Assessment
Scope Checker tool
Post

Is Your CMMC Scope Correct? Try the Free Scope Checker Tool

Struggling to scope your CMMC Level 2 assessment? The new CMMC Scope Checker from Wrightbrained Security’s CMMC Compliance Engine can help change that. This free tool analyzes your assets against DoD guidelines, ensuring you focus controls only where CUI lives, saving time and money. For many defense contractors, the most stressful part of CMMC isn’t...

Security Protection Assets and Security Protection Data in CMMC
Post

Security Protection Assets and Security Protection Data in CMMC

What Are Security Protection Assets (SPAs)? SPAs are the tools, systems, and personnel that provide security functions or capabilities within the CMMC assessment scope of an Organization Seeking Certification (OSC). They protect CUI assets and the broader infrastructure that supports them. A Few Examples of SPAs: Firewalls: Devices or software that regulate network traffic, blocking...

The CMMC Rule and Plans of Action & Milestones (POA&M)
Post

The CMMC Rule and Plans of Action & Milestones (POA&M)

One of the things that I wanted to see in the CMMC Rule was more clarity on utilizing Plans of Action and Milestones (POA&M) for companies that do not fully meet all 110 requirements during their assessment. I’m continuing to dive into the CMMC rule…it’s freaking long. Here is what it says about POA&Ms, the...

Post

The CMMC Rule is FINAL!

Woooohoooo, the long awaited CMMC Rule will be published on the Federal Register on October 15, 2024. The Wrightbrained team has spent some time looking at the document. Clarifications are a big theme. Everyone in the CMMC ecosystem had a lot of questions and there were several that stood out as the most common. I...

VerySecure UAV’s On-Site CMMC Assessment – Physical Security & related domains
Post

VerySecure UAV’s On-Site CMMC Assessment – Physical Security & related domains

Disclaimer: This story is entirely fictional. Any resemblance to actual persons, living or dead, or actual events, or actual companies is purely coincidental and unintended. The characters, companies, and events portrayed are purely a work of fiction. Jil Wright, a Certified CMMC Assessor, has provided this narrative to offer organizations seeking certification an example of what...

CMMC Assessment – SI Domain – MakeBelieve Manufacturing
Post

CMMC Assessment – SI Domain – MakeBelieve Manufacturing

Disclaimer: This story is entirely fictional. Any resemblance to actual persons, living or dead, or actual events, or actual companies is purely coincidental and unintended. The characters, companies, and events portrayed are purely a work of fiction. Jil Wright, a Certified CMMC Assessor, has provided this narrative to offer organizations seeking certification an example of what...

Social Share Buttons and Icons powered by Ultimatelysocial