CMMC Level 1 · ObjectivesSEC / OBJ59
CMMC Level 1 · Reference
CMMC Level 1 Assessment Objectives
The assessment objectives from NIST SP 800-171A. 59 in total across the 6 domains, each mapped to one of the 15 requirements.
Limit system access to authorized users
Access Control · AC.L1-b.1.i- AC.L1-b.1.i(a)authorized users are identified
- AC.L1-b.1.i(b)processes acting on behalf of authorized users are identified
- AC.L1-b.1.i(c)devices (and other systems) authorized to connect to the system are identified
- AC.L1-b.1.i(d)system access is limited to authorized users
- AC.L1-b.1.i(e)system access is limited to processes acting on behalf of authorized users
- AC.L1-b.1.i(f)system access is limited to authorized devices (including other systems)
Limit access to permitted transactions and functions
Access Control · AC.L1-b.1.iiVerify and control connections to external systems
Access Control · AC.L1-b.1.iii- AC.L1-b.1.iii(a)connections to external systems are identified
- AC.L1-b.1.iii(b)the use of external systems is identified
- AC.L1-b.1.iii(c)connections to external systems are verified
- AC.L1-b.1.iii(d)the use of external systems is verified
- AC.L1-b.1.iii(e)connections to external systems are controlled/limited
- AC.L1-b.1.iii(f)the use of external systems is controlled/limited
Control information posted to publicly accessible systems
Access Control · AC.L1-b.1.iv- AC.L1-b.1.iv(a)individuals authorized to post or process information on publicly accessible systems are identified
- AC.L1-b.1.iv(b)procedures to ensure FCI is not posted or processed on publicly accessible systems are identified
- AC.L1-b.1.iv(c)a review process is in place prior to posting of any content to publicly accessible systems
- AC.L1-b.1.iv(d)content on publicly accessible systems is reviewed to ensure that it does not include FCI
- AC.L1-b.1.iv(e)mechanisms are in place to remove and address improper posting of FCI
Identify system users, processes, and devices
Identification and Authentication · IA.L1-b.1.vAuthenticate users before granting access
Identification and Authentication · IA.L1-b.1.vi- IA.L1-b.1.vi(a)the identity of each user is authenticated or verified as a prerequisite to system access
- IA.L1-b.1.vi(b)the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access
- IA.L1-b.1.vi(c)the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access
Sanitize or destroy media before disposal or reuse
Media Protection · MP.L1-b.1.viiLimit physical access to systems and equipment
Physical Protection · PE.L1-b.1.viii- PE.L1-b.1.viii(a)authorized individuals allowed physical access are identified
- PE.L1-b.1.viii(b)physical access to organizational systems is limited to authorized individuals
- PE.L1-b.1.viii(c)physical access to equipment is limited to authorized individuals
- PE.L1-b.1.viii(d)physical access to operating environments is limited to authorized individuals
Escort visitors, log physical access, manage devices
Physical Protection · PE.L1-b.1.ixMonitor and control communications at the boundary
System and Communications Protection · SC.L1-b.1.x- SC.L1-b.1.x(a)the external system boundary is defined
- SC.L1-b.1.x(b)key internal system boundaries are defined
- SC.L1-b.1.x(c)communications are monitored at the external system boundary
- SC.L1-b.1.x(d)communications are monitored at key internal boundaries
- SC.L1-b.1.x(e)communications are controlled at the external system boundary
- SC.L1-b.1.x(f)communications are controlled at key internal boundaries
- SC.L1-b.1.x(g)communications are protected at the external system boundary
- SC.L1-b.1.x(h)communications are protected at key internal boundaries
Separate publicly accessible systems from internal networks
System and Communications Protection · SC.L1-b.1.xiIdentify, report, and correct system flaws
System and Information Integrity · SI.L1-b.1.xii- SI.L1-b.1.xii(a)the time within which to identify system flaws is specified
- SI.L1-b.1.xii(b)system flaws are identified within the specified time frame
- SI.L1-b.1.xii(c)the time within which to report system flaws is specified
- SI.L1-b.1.xii(d)system flaws are reported within the specified time frame
- SI.L1-b.1.xii(e)the time within which to correct system flaws is specified
- SI.L1-b.1.xii(f)system flaws are corrected within the specified time frame
