CMMC Glossary of Terms:
Acronyms, Definitions, & Requirements

These terms are not interchangeable, and an assessor works from the regulation’s definitions rather than the ones your team uses in a meeting.

Every entry below is sourced to the document it comes from. Several of them decide scope, and scope decides what an assessment covers and what it costs.

A

Access Control (AC)

the process of granting or denying specific requests to obtain and use information and related information processing services; and/or entry to specific physical facilities (e.g., Federal buildings, military establishments, or border crossing entrances), as defined in FIPS PUB 201-3 Jan2002 (incorporated by reference, see § 170.2).

(SOURCE 32 CFR 170.4)

Accreditation 

a status pursuant to which a CMMC Assessment and Certification Ecosystem member (person or organization), having met all criteria for the specific role they perform including required ISO/IEC accreditations, may act in that role as set forth in § 170.8 for the Accreditation Body and § 170.9 for C3PAOs. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Accreditation Body

is defined in § 170.8 and means the one organization DoW contracts with to be responsible for authorizing and accrediting members of the CMMC Assessment and Certification Ecosystem, as required. The Accreditation Body must be approved by DoW. At any given point in time, there will be only one Accreditation Body for the DoW CMMC Program. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Adequate Security

protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.

(SOURCE DFARS 252.204-7012)

Advanced Persistent Threat (APT)

an adversary that possesses sophisticated levels of expertise and significant resources that allow it to create opportunities to achieve its objectives by using multiple attack vectors (e.g., cyber, physical, and deception). These objectives typically include establishing and extending footholds within the information technology infrastructure of the targeted organizations for purposes of exfiltrating information, undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period-of-time, adapts to defenders’ efforts to resist it, and is determined to maintain the level of interaction needed to execute its objectives, as is defined in NIST SP 800-39 Mar2011 (incorporated by reference, see § 170.2).

(SOURCE 32 CFR 170.4)

Affirming Official

the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA’s compliance with the CMMC Program requirements and has the authority to affirm the OSA’s continuing compliance with the specified security requirements for their respective organizations. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Agency

(also Federal agency, executive agency, executive branch agency) is any “executive agency,” as defined in 5 U.S.C. 105; the United States Postal Service; and any other independent entity within the executive branch that designates or handles CUI.

(SOURCE 32 CFR 2002.4)

Agency CUI Policies

are the policies the agency enacts to implement the CUI Program within the agency. They must be in accordance with the Order, this part, and the CUI Registry and approved by the CUI EA.

(SOURCE 32 CFR 2002.4)

Agreements and Arrangements 

are any vehicle that sets out specific CUI handling requirements for contractors and other information-sharing partners when the arrangement with the other party involves CUI. Agreements and arrangements include, but are not limited to, contracts, grants, licenses, certificates, memoranda of agreement/arrangement or understanding, and information-sharing agreements or arrangements.

(SOURCE 32 CFR 2002.4)

Assessment

the testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization, as defined in §§ 170.15 through 170.18. (CMMC-custom term) Level 1 Self-Assessment — the term for the activity performed by an OSA to evaluate its own information system when seeking a CMMC Status of Level 1 (Self). Level 2 Self-Assessment — the term for the activity performed by an OSA to evaluate its own information system when seeking a CMMC Status of Level 2 (Self). Level 2 Certification Assessment — the term for the activity performed by a C3PAO to evaluate the information system of an OSC when seeking a CMMC Status of Level 2 (C3PAO). Level 3 Certification Assessment — the term for the activity performed by the DCMA DIBCAC to evaluate the information system of an OSC when seeking a CMMC Status of Level 3 (DIBCAC). POA&M Closeout Self-Assessment — the term for the activity performed by an OSA to evaluate only the NOT MET requirements that were identified with POA&M during the initial assessment, when seeking a CMMC Status of Final Level 2 (Self). POA&M Closeout Certification Assessment — the term for the activity performed by a C3PAO or DCMA DIBCAC to evaluate only the NOT MET requirements that were identified with POA&M during the initial assessment, when seeking a CMMC Status of Final Level 2 (C3PAO) or Final Level 3 (DIBCAC) respectively.

(SOURCE 32 CFR 170.4)

Assessment Findings Report

the final written assessment results by the third-party or government assessment team. The Assessment Findings Report is submitted to the OSC and to the DoW via CMMC eMASS. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Assessment Objective (AO)

a set of determination statements that, taken together, expresses the desired outcome for the assessment of a security requirement. Successful implementation of the corresponding CMMC security requirement requires meeting all applicable assessment objectives defined in NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) or NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2). (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Assessment Team

participants in the Level 2 certification assessment (CMMC Certified Assessors and CMMC Certified Professionals) or the Level 3 certification assessment (DCMA DIBCAC assessors). This does not include the OSC participants preparing for or participating in the assessment. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Asset

an item of value to stakeholders. An asset may be tangible (e.g., a physical item such as hardware, firmware, computing platform, network device, or other technology component) or intangible (e.g., humans, data, information, software, capability, function, service, trademark, copyright, patent, intellectual property, image, or reputation).

(SOURCE 32 CFR 170.4)

Asset Categories

A grouping of assets that process, store or transmit information of similar designation, or provide security protection to those assets. (CMMC-custom term)

(SOURCE32 CFR 170.4)

Authentication

Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.

(SOURCE FIPS PUB 200 Mar2006)

Authorization

The right or a permission that is granted to a system entity to access a system resource.

(SOURCE NIST Glossary)

Authorized

an interim status during which a CMMC Ecosystem member (person or organization), having met all criteria for the specific role they perform other than the required ISO/IEC accreditations, may act in that role for a specified time as set forth in § 170.8 for the Accreditation Body and § 170.9 for C3PAOs. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

Authorized Holder

1. an individual, agency, organization, or group of users that is permitted to designate or handle CUI, in accordance with 32 Code of Federal Regulations (CFR) Part 2002. 2. is an individual, agency, organization, or group of users that is permitted to designate or handle CUI, in accordance with this part.

(SOURCE DoD Mandatory CUI Training – Glossary, CDSE; 32 CFR 2002.4)

ACRONYMS 

AU

Audit and Accountability

(source: Appendix A – Acronyms and Abbreviations)

API

Application Programming Interface

(source: Appendix A – Acronyms and Abbreviations)

AC

Access Control

(source: 32 CFR 170.4)

AES

Advanced Encryption Standard

(source: Appendix A – Acronyms and Abbreviations)

APT

Advanced Persistent Threat

(source: 32 CFR 170.4)

AT

Awareness and Training

(source: 32 CFR 170.4)

B

Basic Assessment 

a contractor’s self-assessment of the contractor’s implementation of NIST SP 800-171 that: (1) Is based on the Contractor’s review of their system security plan(s) associated with covered contractor information system(s); (2) Is conducted in accordance with the NIST SP 800-171 DoD Assessment Methodology; and (3) Results in a confidence level of “Low” in the resulting score, because it is a self-generated score. 

(SOURCE DFARS 252.204-7020)

C

Capability 

a combination of mutually reinforcing controls implemented by technical means, physical means, and procedural means. Such controls are typically selected to achieve a common information security or privacy purpose, as defined in NIST SP 800-37 R2 (incorporated by reference, see § 170.2). 

(SOURCE 32 CFR 170.4)

Classified Information 

is information that Executive Order 13526, “Classified National Security Information,” December 29, 2009 (3 CFR, 2010 Comp., p. 298), or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended, requires agencies to mark with classified markings and protect against unauthorized disclosure. 

(SOURCE 32 CFR 2002.4)

Cloud Service Provider (CSP)

an external company that provides cloud services based on cloud computing. Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

CMMC Assessment and Certification Ecosystem

means the people and organizations described in subpart C of this part. This term is sometimes shortened to CMMC Ecosystem. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

CMMC Assessment Scope

the set of all assets in the OSA’s environment that will be assessed against CMMC security requirements. (CMMC-custom term)

(SOURCE  32 CFR 170.4)

CMMC Assessor and Instructor Certification Organization (CAICO)

the organization responsible for training, testing, authorizing, certifying, and recertifying CMMC certified assessors, certified instructors, and certified professionals. (CMMC-custom term)

(SOURCE 32 CFR 170.4)

CMMC Security Requirements

the 15 Level 1 requirements listed in the 48 CFR 52.204-21(b)(1), the 110 Level 2 requirements from NIST SP 800-171 R2 (incorporated by reference, see § 170.2), and the 24 Level 3 requirements selected from NIST SP 800-172 Feb2021 (incorporated by reference, see § 170.2).

(SOURCE 32 CFR 2002.4)

CMMC Status 

the result of meeting or exceeding the minimum required score for the corresponding assessment. The CMMC Status of an OSA information system is officially stored in SPRS and additionally presented on a Certificate of CMMC Status, if the assessment was conducted by a C3PAO or DCMA DIBCAC. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

CMMC Third-Party Assessment Organization (C3PAO) 

an organization that has been authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments and has the roles and responsibilities identified in § 170.9. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Compromise 

disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred. 

(SOURCE DFARS 252.204-7012)

Contractor 

any individual or other legal entity that is awarded a Federal Government contract or subcontract under a Federal Government contract. 

(SOURCE 29 CFR 10.2)

Contractor Risk Managed Asset (CRMA) 

Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place. Assets are not required to be physically or logically separated from CUI assets. 

(SOURCE 32 CFR 170.4)

Controlled Environment 

is any area or space an authorized holder deems to have adequate physical or procedural controls (e.g., barriers or managed access controls) to protect CUI from unauthorized access or disclosure. 

(SOURCE 32 CFR 2002.4)

Controlled Unclassified Information (CUI) 

1. is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. 2. Unclassified information requiring safeguarding and dissemination controls, consistent with applicable law, regulation, or government-wide policy. 

(SOURCE 32 CFR 2002.4; DoD Mandatory CUI Training – Glossary, CDSE)

Controlled Unclassified Information Asset (CUIA) 

assets that can process, store, or transmit CUI. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Covered Contractor Information System 

an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information. 

(SOURCE DFARS 252.204-7012)

Covered Defense Information (CDI) 

unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) Registry at http://www.archives.gov/cui/registry/category-list.html, that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and Governmentwide policies. 

(SOURCE DFARS 252.204-7012)

CUI Basic 

Subset of CUI for which the authorizing law, regulation, or government-wide policy does not set out specific handling or dissemination controls. Agencies handle CUI Basic according to the uniform set of controls set forth in DoDI 5200.48 and the DoW CUI Registry. 

(SOURCE DoD Mandatory CUI Training – Glossary, CDSE; 32 CFR 2002.4)

CUI Specified 

Subset of CUI in which the authorizing law, regulation, or government wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic. 

(SOURCE DoD Mandatory CUI Training – Glossary, CDSE; 32 CFR 2002.4)

Cyber Incident 

actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein. 

(SOURCE DFARS 252.204-7012)

ACRONYMS 

C3PAO

CMMC Third-Party Assessment Organization

(source: 32 CFR 170.4)

CA

Security Assessment

(source: 32 CFR 170.4)

CAICO

CMMC Assessors and Instructors Certification Organization

(source: 32 CFR 170.4)

CAGE

Commercial and Government Entity

(source: 32 CFR 170.4)

CCP

 CMMC-Certified Professional 

(source: 32 CFR 170.4)

CIO

Chief Information Office

(source: 32 CFR 170.4)

CM

Configuration Management

(source: 32 CFR 170.4)

CMMC

Cybersecurity Maturity Model Certification

(source: 32 CFR 170.4)

CCA

CMMC-Certified Assessor

(source: 32 CFR 170.4)

CCI

CMMC-Certified Instructor

(source: 32 CFR 170.4)

CSP

Cloud Service Provider

(source: 32 CFR 170.4)

CUI

Controlled Unclassified Information

(source: 32 CFR 170.4)

D

DCMA DIBCAC High Assessment

an assessment that is conducted by Government personnel in accordance with NIST SP 800-171A Jun2018 and leveraging specific guidance in the DoD Assessment Methodology.

 

(SOURCE 32 CFR 170.4)

Defense Industrial Base (DIB)

the Department of Defense, Government, and private sector worldwide industrial complex with capabilities to perform research and development, design, produce, and maintain military weapon systems, subsystems, components, or parts to satisfy military requirements.

(SOURCE 32 CFR 236.2)

DoD now DoW Assessment Methodology (DoDAM)

documents a standard methodology that enables a strategic assessment of a contractor’s implementation of NIST SP 800-171 R2, a requirement for compliance with 48 CFR 252.204-7012.

(SOURCE 32 CFR 170.4)

ACRONYMS 

DCMA

Defense Contract Management Agency

(source: 32 CFR 170.4)

DFARS

Defense Federal Acquisition Regulation Supplement

(source: 32 CFR 170.4)

DIB

Defense Industrial Base

(source: 32 CFR 170.4)

DIBCAC

DCMA’s Defense Industrial Base Cybersecurity Assessment Center

(source: 32 CFR 170.4)

DoD

Department of Defense

(source: 32 CFR 170.4)

DoW

Department of War

(source: 32 CFR 170.4)

E

Enduring Exception 

a special circumstance or system where remediation and full compliance with CMMC security requirements is not feasible. Examples include systems required to replicate the configuration of fielded systems, medical devices, test equipment, OT, and IoT. No operational plan of action is required but the circumstance must be documented within a system security plan. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

External Service Provider (ESP) 

external people, technology, or facilities that an organization utilizes for provision and management of IT and/or cybersecurity services on behalf of the organization. In the CMMC Program, CUI or Security Protection Data must be processed, stored, or transmitted on the ESP assets to be considered an ESP. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

ACRONYMS 

eMass

Enterprise Mission Assurance Support Service

(source: 32 CFR 170.4)

ESP

External Service Provider

(source: 32 CFR 170.4)

F

Federal Contract Information (FCI) 

information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public or simple transactional information, such as that necessary to process payments. 

(SOURCE 48 CFR 4.1901)

Federal Information System 

an information system used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency. 

(SOURCE 32 CFR 2002.4)

FIPS-Validated Cryptography 

A cryptographic module validated by the Cryptographic Module Validation Program (CMVP) to meet requirements specified in FIPS Publication 140-3 (as amended). 

(SOURCE NIST SP 800-171r3; NIST SP 800-53 Rev. 5)

ACRONYMS 

FAR

Federal Acquisition Regulation

(source: 32 CFR 170.4)

FCI

Federal Contract Information

(source: 32 CFR 170.4)

FedRAMP

 Federal Risk and Authorization Management Program

(source: 32 CFR 170.4)

FIPS

Federal Information Processing Standard

(source: Appendix A – Acronyms and Abbreviations)

FRME

Federal Risk and Authorization Management Program (FedRAMP) Moderate Equivalent as outlined in DFARS 252.204-7012

(source: DFARS 252.204-7012)

G

Government Furnished Equipment (GFE) 

property in the possession of, or directly acquired by, the Government and subsequently furnished to the contractor for performance of a contract. Government-furnished property includes, but is not limited to, spares and property furnished for repair, maintenance, overhaul, or modification. 

(SOURCE 48 CFR 45.101)

ACRONYMS 

GFE

 Government Furnished Equipment

(source: 32 CFR 170.4)

H

Handling 

any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information. 

(SOURCE 32 CFR 2002.4)

High Assessment 

an assessment that is conducted by Government personnel using NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information. Results in a confidence level of “High” in the resulting score. 

(SOURCE DFARS 252.204-7020)

I

Industrial Control Systems (ICS) 

means a general term that encompasses several types of control systems, including supervisory control and data acquisition (SCADA) systems, distributed control systems (DCS), and other control system configurations that are often found in the industrial sectors and critical infrastructures, such as Programmable Logic Controllers (PLC). 

(SOURCE 32 CFR 170.4)

Information System (IS) 

A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. 

(SOURCE NIST SP 800-171 R2; DFARS 252.204-7012)

Internet of Things (IoT) 

the network of devices that contain the hardware, software, firmware, and actuators which allow the devices to connect, interact, and freely exchange data and information, as defined in NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2). 

(SOURCE 32 CFR 170.4)

Incident 

An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies. 

(SOURCE FIPS 200)

ACRONYMS 

IA

Identification and Authentication

(source: 32 CFR 170.4)

ICS

Industrial Control System

(source: 32 CFR 170.4)

IoT

 Internet of Things

(source: 32 CFR 170.4)

IR

 Incident Response

(source: Appendix A – Acronyms and Abbreviations)

IS

Information System

(source: 32 CFR 170.4)

IT

Information Technology

(source: 32 CFR 170.4)

L

Lawful Government Purpose 

any activity, mission, function, operation, or endeavor that the U.S. Government authorizes or recognizes as within the scope of its legal authorities or the legal authorities of non-executive branch entities (such as state and local law enforcement). 

(SOURCE 32 CFR 2002.4)

Limited Dissemination Control (LDC) 

1. utilized within DoW to limit access to certain agency-specific CUI within an organization. 2. any CUI EA-approved control that agencies may use to limit or specify CUI dissemination. 

(SOURCE DoD Mandatory CUI Training – Glossary, CDSE; 32 CFR 2002.4)

ACRONYMS 

LAN

Local Area Network

(source: Appendix A – Acronyms and Abbreviations)

M

Malicious Software 

computer software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of an information system. This definition includes a virus, worm, Trojan horse, or other code-based entity that infects a host, as well as spyware and some forms of adware. 

(SOURCE DFARS 252.204-7012)

Medium Assessment 

an assessment conducted by the Government that consists of a review of a contractor’s Basic Assessment, a thorough document review, and discussions with the contractor to obtain additional information or clarification, as needed. Results in a confidence level of “Medium” in the resulting score. 

(SOURCE DFARS 252.204-7020)

ACRONYMS 

MA

Maintenance

(source: 32 CFR 170.4)

MFA

Multifactor Authentication

(source: Appendix A – Acronyms and Abbreviations)

MP

Media Protection

(source: 32 CFR 170.4)

MSSP

Managed Security Service Provider

(source: 32 CFR 170.4)

N

National Security System 

a special type of information system (including telecommunications systems) whose function, operation, or use is defined in National Security Directive 42 and 44 U.S.C. 3542(b)(2). 

(SOURCE 32 CFR 2002.4)

ACRONYMS 

NARA

National Archives and Records Administration

(source: 32 CFR 170.4)

NIST

National Institute of Standards and Technology

(source: 32 CFR 170.4)

O

Operational Plan of Action (OPA) 

as used in security requirement CA.L2-3.12.2, means the formal artifact which identifies temporary vulnerabilities and temporary deficiencies in implementation of requirements and documents how they will be mitigated, corrected, or eliminated. An operational plan of action does not identify a timeline for remediation and is not the same as a POA&M. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Operational Technology (OT) 

means programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems or devices detect or cause a direct change through the monitoring or control of devices, processes, and events. 

(SOURCE 32 CFR 170.4)

Organization Seeking Assessment (OSA) 

the entity seeking to undergo a self-assessment or certification assessment for a given information system for the purposes of achieving and maintaining any CMMC Status. The term OSA includes all Organizations Seeking Certification (OSCs). (CMMC-custom term) 

(SOURCE 32 CFR 170.4) 

Organization Seeking Certification (OSC) 

the entity seeking to undergo a certification assessment for a given information system for the purposes of achieving and maintaining the CMMC Status of Level 2 (C3PAO) or Level 3 (DIBCAC). An OSC is also an OSA. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Out Of Scope (OOS) Asset 

assets that cannot process, store, or transmit CUI because they are physically or logically separated from information systems that do process, store, or transmit CUI, or are inherently unable to do so. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

ACRONYMS 

ODP

Organization-Defined Parameter

(source: 32 CFR 170.4)

OSA

Organization Seeking Assessment

(source: 32 CFR 170.4)

OSC

Organization Seeking Certification

(source: 32 CFR 170.4)

OT

Operational Technology

(source: 32 CFR 170.4)

P

Plan of Action and Milestones (POA&M) 

a document that identifies tasks needing to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in NIST SP 800-115 Sept2008 (incorporated by reference, see § 170.2). 

(SOURCE 32 CFR 170.4)

Prime Contractor 

a person who has entered into a prime contract with the United States. 

(SOURCE 48 CFR 3.502-1)

Process, Store, or Transmit 

data can be used by an asset (e.g., accessed, entered, edited, generated, manipulated, or printed); data is inactive or at rest on an asset (e.g., located on electronic media, in system component memory, or in physical format such as paper documents); or data is being transferred from one asset to another asset (e.g., data in transit using physical or digital transport methods). (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

ACRONYMS 

PPI

Personally Identifiable Information

(source: 32 CFR 170.4)

POA&M

Plans of Action and Milestones

(source: 32 CFR 170.4)

R

Rapidly Report 

within 72 hours of discovery of any cyber incident. 

(SOURCE DFARS 252.204-7012)

Risk 

a measure of the extent to which an entity is threatened by a potential circumstance or event, and is typically a function of: (i) The adverse impacts that would arise if the circumstance or event occurs; and (ii) The likelihood of occurrence, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2). 

(SOURCE 32 CFR 170.4)

Risk Assessment (RA) 

the process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. 

(SOURCE 32 CFR 170.4)

ACRONYMS 

RA

Risk Assessment

(source: Appendix A – Acronyms and Abbreviations)

RM

Risk Management

(source: 32 CFR 170.4)

S

Security Protection Assets (SPA) 

assets providing security functions or capabilities for the OSA’s CMMC Assessment Scope. (CMMC-custom term) 

(SOURCE 32 CFR 170.4 and CMMC Level 2 Scoping Guide 2.13)

Security Protection Data (SPD) 

data stored or processed by Security Protection Assets (SPA) that are used to protect an OSC’s assessed environment. SPD is security relevant information and includes but is not limited to: configuration data required to operate an SPA, log files generated by or ingested by an SPA, data related to the configuration or vulnerability status of in-scope assets, and passwords that grant access to the in-scope environment. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Specialized Asset (SA) 

types of assets considered specialized assets for CMMC: Government Furnished Equipment, Internet of Things (IoT) or Industrial Internet of Things (IIoT), Operational Technology (OT), Restricted Information Systems, and Test Equipment. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Subcontractor 

any person, other than the prime contractor, who offers to furnish or furnishes any supplies, materials, equipment, or services of any kind under a prime contract or a subcontract entered into in connection with such prime contract. 

(SOURCE 48 CFR 3.502-1)

System Security Plan (SSP) 

the formal document that provides an overview of the security requirements for an information system or an information security program and describes the security controls in place or planned for meeting those requirements. 

(SOURCE 32 CFR 170.4)

ACRONYMS 

SC

System and Communications Protection

(source: 32 CFR 170.4)

SIEM

Security Information and Event Management

(source: 32 CFR 170.4)

SOC

Security Operations Center

(source: NIST SP 800-53)

SPRS

Supplier Performance Risk System

(source: 32 CFR 170.4)

SSP

System Security Plan

(source: 32 CFR 170.4)

T

Technical Information 

technical data or computer software, as those terms are defined in the clause at DFARS 252.227-7013. Examples of technical information include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, technical orders, catalog-item identifications, data sets, studies and analyses and related information, and computer software executable code and source code. 

(SOURCE DFARS 252.204-7012)

Temporary Deficiency 

a condition where remediation of a discovered deficiency is feasible, and a known fix is available or is in process. The deficiency must be documented in an operational plan of action. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

Test Equipment 

hardware and/or associated IT components used in the testing of products, system components, and contract deliverables. (CMMC-custom term) 

(SOURCE 32 CFR 170.4)

ACRONYMS 

TLS

Transport Layer Security

(source: (source: Appendix A – Acronyms and Abbreviations)

U

Unauthorized Disclosure 

occurs when an authorized holder of CUI intentionally or unintentionally discloses CUI without a lawful Government purpose, in violation of restrictions imposed by safeguarding or dissemination controls, or contrary to limited dissemination controls. 

(SOURCE 32 CFR 2002.4)

User 

an individual, or (system) process acting on behalf of an individual, authorized to access a system, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2). 

(SOURCE 32 CFR 170.4)

ACRONYMS 

USB

Universal Serial Bus

(source: Appendix A – Acronyms and Abbreviations)

V

ACRONYMS 

VDI

Virtual Desktop Infrastructure

(source: 32 CFR 170.4)

VLAN

Virtual Local Area Network

(source: Appendix A – Acronyms and Abbreviations)

VPN

Virtual Private Network

(source: Appendix A – Acronyms and Abbreviations)

VoIP

 Voice over Internet Protocol

(source: Appendix A – Acronyms and Abbreviations)

W

Working papers 

documents or materials, regardless of form, that an agency or user expects to revise prior to creating a finished product. 

(SOURCE 32 CFR 2002.4)

ACRONYMS 

WPA2-PSK

WiFi Protected Access-Pre-shared Key

(source: Appendix A – Acronyms and Abbreviations)

The Definitions Are Settled. Your Scope Is Not.

Every definition above is fixed in the regulation. Which of your systems fall inside the boundary those definitions describe is not, and that decision sets what an assessment covers and what it costs.

Which systems would you have to defend as in scope today?