CMMC Level 1 · ObjectivesSEC / OBJ59

CMMC Level 1 · Reference

CMMC Level 1 Assessment Objectives

The assessment objectives from NIST SP 800-171A. 59 in total across the 6 domains, each mapped to one of the 15 requirements.

Limit system access to authorized users

Access Control · AC.L1-b.1.i

Limit access to permitted transactions and functions

Access Control · AC.L1-b.1.ii

Verify and control connections to external systems

Access Control · AC.L1-b.1.iii

Control information posted to publicly accessible systems

Access Control · AC.L1-b.1.iv

Identify system users, processes, and devices

Identification and Authentication · IA.L1-b.1.v

Authenticate users before granting access

Identification and Authentication · IA.L1-b.1.vi

Sanitize or destroy media before disposal or reuse

Media Protection · MP.L1-b.1.vii

Limit physical access to systems and equipment

Physical Protection · PE.L1-b.1.viii

Escort visitors, log physical access, manage devices

Physical Protection · PE.L1-b.1.ix

Monitor and control communications at the boundary

System and Communications Protection · SC.L1-b.1.x

Separate publicly accessible systems from internal networks

System and Communications Protection · SC.L1-b.1.xi

Identify, report, and correct system flaws

System and Information Integrity · SI.L1-b.1.xii

Protect against malicious code

System and Information Integrity · SI.L1-b.1.xiii

Keep malicious code protection current

System and Information Integrity · SI.L1-b.1.xiv

Perform periodic and real-time scans

System and Information Integrity · SI.L1-b.1.xv