CMMC
Cybersecurity Maturity Model Certification
Maturity levels for protecting federal contract information and controlled unclassified information.
- Version
- 2.0
- Authority
- US DoD
Activate as many standards as you need. Attesta records the framework version, creates the applicable requirements, and connects them to canonical controls so one implementation is never rebuilt twice.
Cybersecurity Maturity Model Certification
Maturity levels for protecting federal contract information and controlled unclassified information.
FedRAMP Moderate Baseline
Standardised security authorization baseline for cloud services used by US federal agencies.
EU General Data Protection Regulation
Obligations for lawful, secure and accountable processing of personal data of EU data subjects.
HIPAA Security Rule
Administrative, physical and technical safeguards for electronic protected health information.
HITRUST CSF
Prescriptive, risk-based control framework harmonising multiple healthcare and security standards.
ISO/IEC 27001 Information Security Management
Requirements for establishing, maintaining and continually improving an information security management system.
ISO/IEC 42001 AI Management System
Requirements for an artificial intelligence management system, including AI risk and impact assessment.
NIST SP 800-53 Security and Privacy Controls
Comprehensive catalogue of security and privacy controls for information systems and organizations.
NIST Cybersecurity Framework
Govern, Identify, Protect, Detect, Respond and Recover outcomes for managing cybersecurity risk.
Payment Card Industry Data Security Standard
Requirements for protecting cardholder data in payment environments.
SOC 2 Trust Services Criteria
Trust services criteria for security, availability, processing integrity, confidentiality and privacy.
44 maintained controls sit underneath the frameworks. Attesta only claims a control satisfies a framework when a maintained mapping exists.
| Control | Domain | Description |
|---|---|---|
| CC-ACC-01 Unique user identification | Access Control | Every person and service accessing systems is assigned a unique, attributable identifier. |
| CC-ACC-02 Multi-factor authentication | Access Control | Multi-factor authentication is enforced for remote, administrative and privileged access. |
| CC-ACC-03 Least-privilege access provisioning | Access Control | Access is granted on a documented, role-based least-privilege basis and approved before issue. |
| CC-ACC-04 Periodic access review | Access Control | User and privileged access rights are reviewed on a defined schedule and corrected where needed. |
| CC-ACC-05 Timely access revocation | Access Control | Access is revoked promptly on termination or role change under a documented process. |
| CC-AIG-01 AI system inventory and impact assessment | AI Governance | AI systems are inventoried and assessed for impact on individuals and the organization. |
| CC-AIG-02 AI oversight and human review | AI Governance | Human oversight, review and escalation are defined for AI-assisted decisions. |
| CC-AST-01 Asset inventory | Asset Management | A current inventory of hardware, software, data stores and services is maintained with owners. |
| CC-AST-02 Data classification and handling | Asset Management | Information is classified and handled according to defined sensitivity levels. |
| CC-AST-03 Secure media and asset disposal | Asset Management | Media and assets are sanitised or destroyed securely before disposal or reuse. |
| CC-BCP-01 Backup and restoration | Resilience | Backups are performed, protected and restore-tested on a defined schedule. |
| CC-BCP-02 Business continuity and disaster recovery plan | Resilience | Continuity and recovery plans define objectives, responsibilities and recovery targets. |
| CC-BCP-03 Continuity plan testing | Resilience | Continuity and recovery plans are exercised periodically and results drive improvement. |
| CC-CHG-01 Change management | Change Management | Changes are requested, reviewed, approved, tested and recorded before release. |
| CC-CHG-02 Secure development lifecycle | Change Management | Security requirements, code review and testing are embedded in the development lifecycle. |
| CC-CHG-03 Environment separation | Change Management | Development, test and production environments are separated with controlled promotion. |
| CC-CRY-01 Encryption in transit | Data Protection | Data in transit is protected with current, strong cryptographic protocols. |
| CC-CRY-02 Encryption at rest | Data Protection | Sensitive data at rest is encrypted using approved algorithms and managed keys. |
| CC-CRY-03 Key management | Data Protection | Cryptographic keys are generated, stored, rotated and retired under a documented procedure. |
| CC-GOV-01 Information security policy set | Governance | A management-approved policy set is maintained, communicated and reviewed at least annually. |
| CC-GOV-02 Security roles and responsibilities | Governance | Security roles, responsibilities and accountable owners are defined and assigned. |
| CC-GOV-03 Risk assessment process | Governance | Risks are identified, analysed, treated and reviewed under a documented, repeatable process. |
| CC-GOV-04 Management review of security programme | Governance | Leadership reviews security performance, risks and improvement actions at planned intervals. |
| CC-HRS-01 Personnel screening | People Security | Background verification is performed for personnel proportionate to role and data access. |
| CC-HRS-02 Security awareness training | People Security | Personnel complete security and privacy awareness training at onboarding and periodically. |
| CC-HRS-03 Terms of employment and confidentiality | People Security | Employment terms include security responsibilities and confidentiality obligations. |
| CC-INC-01 Incident response plan | Incident Management | A documented incident response plan defines roles, severity levels and escalation paths. |
| CC-INC-02 Incident detection and reporting | Incident Management | Personnel and systems have defined channels to report suspected security incidents. |
| CC-INC-03 Breach notification process | Incident Management | Regulatory and contractual breach notification obligations are documented and exercised. |
| CC-OPS-01 Centralised logging | Security Operations | Security-relevant events are logged centrally, protected from tampering, and retained. |
| CC-OPS-02 Log review and alerting | Security Operations | Logs and alerts are monitored and investigated under a defined process. |
| CC-OPS-03 Endpoint protection | Security Operations | Endpoints run managed protective software with central visibility and enforcement. |
| CC-OPS-04 Network segmentation and boundary protection | Security Operations | Network boundaries are controlled and sensitive environments are segmented. |
| CC-PHY-01 Physical access control | Physical Security | Physical access to facilities and equipment is restricted, logged and reviewed. |
| CC-PHY-02 Mobile and portable device security | Physical Security | Mobile and portable devices are encrypted, managed and remotely wipeable. |
| CC-PRV-01 Lawful basis and privacy notices | Privacy | Personal data processing has a documented lawful basis and transparent notices. |
| CC-PRV-02 Data subject rights handling | Privacy | Requests to access, correct, delete or port personal data are handled within required timeframes. |
| CC-PRV-03 Data minimisation and retention | Privacy | Personal data is limited to what is necessary and deleted per a retention schedule. |
| CC-TPM-01 Third-party due diligence | Third-Party Management | Suppliers are risk-assessed before engagement and re-assessed on a defined cycle. |
| CC-TPM-02 Contractual security requirements | Third-Party Management | Contracts include security, privacy and breach notification obligations. |
| CC-TPM-03 Ongoing supplier monitoring | Third-Party Management | Supplier performance and security posture are monitored throughout the relationship. |
| CC-VUL-01 Vulnerability scanning | Vulnerability Management | Systems are scanned for vulnerabilities on a defined schedule. |
| CC-VUL-02 Patch and remediation SLAs | Vulnerability Management | Vulnerabilities are remediated within severity-based timeframes and tracked to closure. |
| CC-VUL-03 Penetration testing | Vulnerability Management | Independent penetration testing is performed periodically and findings are remediated. |