Exit CMMC-CCA Certified CMMC Assessor (CCA)
Question 4 of 5
0% complete
Q4 Single choice

When discussing the OSC's proposed assessment scope, the Lead Assessor learned that some laptops and workstations share a network with CUI assets, but their users do not work with CUI. These assets do not store CUI or run applications that process CUI. Reviewing the OSC's SSP, the implemented risk-based security policies, procedures, and practices raised questions and were found to be deficient.

What can the Lead Assessor do in this scenario?

  • A

    Inform the C3PAO so as to obtain advice on the way forward.

  • B

    Advise the OSC PoC or Assessment Official to address the identified deficiencies.

  • C

    Conduct a limited spot check to identify risks.

  • D

    Validate the scope because the assets do not interact with CUI.