Subcontractor CMMC Tracker

System and Information Integrity (SI): the 7 CMMC Level 2 requirements a subcontractor self-assesses

The System and Information Integrity family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

7
CMMC L2 SI.L2-3.14.1Flaw Remediation 5 points in the score

Identify system flaws, report them, and correct them within a timely period.

What an assessor asks to see: Flaw identification sources and process; Patch and remediation records with dates showing timeliness; Defined timeframes for correction by severity
Where subcontractors usually fall short: Flaws identified but remediation timeframes undefined; Patching covers operating systems only, omitting applications and firmware; Reporting step absent so flaws are not tracked
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 SI.L2-3.14.2Malicious Code Protection 5 points in the score

Provide malicious code protection at the points in the system where such code is likely to enter or execute.

What an assessor asks to see: Identification of designated protection locations, endpoints and gateways; Malicious code protection deployment and coverage reporting; Configuration showing protection is active
Where subcontractors usually fall short: Endpoints covered while email and web gateways are not; Coverage gaps on servers and non standard platforms; Protection installed but disabled or in passive mode
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 SI.L2-3.14.3Security Alerts & Advisories 5 points in the score

Monitor security alerts and advisories and take action in response to them.

What an assessor asks to see: Subscriptions or sources for security alerts and advisories; Records of alerts received and assessed; Evidence of action taken in response
Where subcontractors usually fall short: Advisories received but never triaged; No defined owner for monitoring advisories; Action taken informally with no record
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 SI.L2-3.14.4Update Malicious Code Protection 5 points in the score

Keep malicious code protection mechanisms current by applying new releases as they are issued.

What an assessor asks to see: Update configuration for signatures and engine versions; Reporting showing current update status across the estate; Evidence of remediation for out of date endpoints
Where subcontractors usually fall short: Signatures updated while the engine version lags; Offline or infrequently connected devices left stale; Update failures unmonitored
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 SI.L2-3.14.5System & File Scanning 3 points in the score

Run periodic scans of systems and real time scans of files arriving from external sources as those files are downloaded, opened or executed.

What an assessor asks to see: Scheduled scan configuration and completion records; Real time scanning configuration covering download, open and execute events; Coverage reporting across in scope systems
Where subcontractors usually fall short: Periodic scanning enabled while real time scanning is off; Real time scanning limited to downloads only; Scan exclusions broad and unreviewed
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 SI.L2-3.14.6Monitor Communications for Attacks 5 points in the score

Watch organizational systems, and both inbound and outbound traffic, for attacks and for indicators that an attack may be developing.

What an assessor asks to see: Monitoring capability configuration covering inbound and outbound traffic; Detection rules or signatures and their tuning records; Records of detected events and the response taken
Where subcontractors usually fall short: Inbound traffic monitored while outbound is not; Monitoring deployed but alerts unreviewed; Encrypted traffic unmonitored with no compensating visibility
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 SI.L2-3.14.7Identify Unauthorized Use 3 points in the score

Define what constitutes authorized use of organizational systems, and identify use that falls outside that definition.

What an assessor asks to see: Documented definition of authorized system use; Monitoring or detection capability identifying use outside that definition; Records of identified unauthorized use and the response
Where subcontractors usually fall short: Authorized use never defined so unauthorized use cannot be identified; Detection focused on external attack while insider misuse is unaddressed; Identified misuse not recorded or acted on
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)