RSI Security

Overview of CMMC Level 3 Requirements

HIPAA

Welcome to the third installment of our series on the Cybersecurity Maturity Model Certification (CMMC), a framework required for companies contracting with the US Department of Defense (DoD). In this guide, we’ll break down everything you need to know about CMMC Level 3. For information about other levels of the CMMC, see our guides, levels 1, 2, 4, and 5.

Overview of CMMC Level 3 Requirements

The key to complying with CMMC requirements at all levels is understanding exactly what is required. To that end, this blog (and the whole series) is built around descriptions of all practices for each given level, sourced directly from CMMC Volume 1.02 from March 2020

Like other articles in the series, we’ll begin with a brief overview (or recap) of the whole CMMC Framework, including baseline definitions and concepts that apply across all levels. Then, as with installment 2, the main structure below breaks down as follows:

Let’s get started!

 

CMMC Framework Review

The CMMC exists in order to shore up cyberdefense across the vast network of DoD contractors. This includes especially the supply chain that makes up the Defense Industrial Base sector (DIB), which hosts two particularly sensitive forms of data:

To protect FCI and CUI, the Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)) worked with University Affiliated Research Centers (UARCs) and Federally Funded Research and Development Centers (FFRDs) to develop the CMMC.

Structurally, the CMMC Framework consists of the following major elements:

The Framework’s controls combine elements of several other frameworks. The National Institute for Standards and Technology (NIST) Special Publication 800-171 informs protections for CUI in accordance with Defense Federal Acquisition Regulation Supplement (DFARS) Clause 252- 204-7012. And Federal Acquisition Regulation (FAR) Clause 52.203-21 informs FCI protections.

 

Assess your CMMC compliance

 

CMMC Level 3 Controls Deep Dive

Unlike Level 2, Level 3 indicates culmination. Building on the preparatory and transitional work of the prior levels, the focus of Level 3 is finally achieving the goal of CUI protection, achieving incorporation of all of NIST SP 800-171, along with many other protections from other sources.

This means achieving “good cyber hygiene” across practices and ensuring that processes are further institutionalized: not only implemented and documented, but managed. At Level 3, you need to have an action plan in place with adequate resources for long-term implementation.

For those keeping count, Level 3 adds an additional 58 practices for a whopping total of 130. Of these 58, 45 come from NIST SP 800-171, whereas 13 come from other, disparate sources.

Let’s take a close look at all the practices, broken down by domain.

Level 3 Access Control Practices

There are 8 new AC controls introduced at Level 3:

 

Level 3 Asset Management Practice

The first AM control is introduced at Level 3:

 

Level 3 Audit and Accountability Practices

There are 7 new AU controls introduced at Level 3:

 

Level 3 Awareness and Training Practice

There is just 1 new AT control introduced at Level 3:

 

Level 3 Configuration Management Practices

There are 3 new CM controls introduced at Level 3:

 

Level 3 Identification and Authentication Practices

There are 4 new IA controls introduced at Level 3:

 

Level 3 Incident Response Practices

There are 2 new IR controls introduced at Level 3:

 

Level 3 Maintenance Practices

There are 2 new MA controls introduced at Level 3:

 

Level 3 Media Protection Practices

There are 3 new MP controls introduced at Level 3:

 

Level 3 Physical Protection Practice

There are is just 1 new PE control introduced at Level 3:

Level 3 Recovery Practice

There is just 1 new RE control introduced at Level 3:

 

Level 3 Risk Management Practices

There are 3 new RM controls introduced at Level 3:

 

Here are a few more articles to help you learn more about CMMC :

 

Level 3 Security Assessment Practices

There are 2 new CA controls introduced at Level 3:

 

Level 3 Situational Awareness Practice

The first SA control is introduced at Level 3:

 

Level 3 System and Communications Protection Practices

There are a whopping 15 new SC controls introduced at Level 3:

 

Level 3 System and Information Integrity Practices

There are 3 new SI controls introduced at Level 3:

 

How to Meet CMMC Level 3 Requirements

At Level 3, there are 130 total practices you need to worry about — all 72 from Level 2, plus the 58 added in Level 3. Furthermore, institutionalization is also more challenging at this level, since you need to move from mere documentation to a more active management of processes.

That means demonstrating to your assessor that you have a plan and resources in place to keep these practices up and running over the long-term. Speaking of assessor…

It takes a Certified Third Party Assessment Organization (C3PAO), qualified by the CMMC Accreditation Body, to grant certification. And the best C3PAOs, like RSI Security, do more than certify. We are also happy to walk you through all stages of implementation, documentation, and management of your processes. Our  CMMC services are key to certification at all levels.

 

Robust, Professional CUI Protection

Here at RSI Security, we are ready and willing to help you with all of your cybersecurity needs. From CMMC certification across all levels of compliance more broadly, to basic architecture implementation — we have you covered. Our team of experts has provided cybersecurity solutions to all kinds of companies for over a decade. We’re happy to help you serve the DoD.

Contact RSI Security today to see just how easy CMMC level 3 certification can be!

 


Speak with a CMMC compliance expert today – Schedule a free consultation

Exit mobile version