CMMC Level 1 · Assessment ObjectiveSEC / OBJSC.L1-b.1.x(a)
System and Communications Protection · SC.L1-b.1.x(a)
The external system boundary is defined
An assessment objective under requirement SC.L1-b.1.x, Boundary Protection, in the System and Communications Protection domain.
Objective Statement
the external system boundary is defined
Source · NIST SP 800-171A
Objective identity
- Framework
- Cybersecurity Maturity Model Certification · Level 1
- Domain
- System and Communications Protection (SC)
- Objective ID
- SC.L1-b.1.x(a)
- Parent Requirement
- SC.L1-b.1.x · Monitor and control communications at the boundary
Assessment Procedures
The official government assessment method for this objective, from NIST SP 800-171A. An assessor examines artifacts, interviews people, and tests mechanisms to determine the result.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system security plan
- system design documentation
- network diagrams
- boundary protection hardware and software configuration
- other relevant documents or records
Interview
- Personnel with boundary protection responsibilities
- system or network administrators
- personnel with information security responsibilities
Test
- Mechanisms implementing boundary protection capability
- organizational processes for monitoring and controlling communications at the system boundary
Related Objectives
- SC.L1-b.1.x(b)key internal system boundaries are defined
- SC.L1-b.1.x(c)communications are monitored at the external system boundary
- SC.L1-b.1.x(d)communications are monitored at key internal boundaries
- SC.L1-b.1.x(e)communications are controlled at the external system boundary
- SC.L1-b.1.x(f)communications are controlled at key internal boundaries
- SC.L1-b.1.x(g)communications are protected at the external system boundary
- SC.L1-b.1.x(h)communications are protected at key internal boundaries
Source Authority
- Primary Authority
- NIST SP 800-171A
- Requirement Authority
- FAR 52.204-21(b)(1)
- Program Authority
- 32 CFR 170.15(c)(1)(ii) Table 2
- Framework Version
- CMMC Assessment Guide, Level 1 v2.13 (September 2024)
- Effective Date
- 2024-12-16
- Last Verified
- 2026-08
Build the Record Behind This
AssessrLog logs the determination for this objective with its evidence and source record, so your Level 1 self-assessment stays traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make.
