Objective
The DoD has released the Cybersecurity Maturity Model Certification (CMMC) to ensure appropriate levels of cybersecurity controls and processes are adequate and in place to protect Controlled Unclassified Information (CUI) on DoD contractor systems.
The course starts with details about the CMMC model structure (domains, capabilities, practices, and processes), how the model works, five process maturity levels, and five technical practices. The course learning includes knowledge about NIST 800- 171 domains, Personnel Security, Physical Protection, Risk Management, Security Assessment, System & Communications Protection, System & Information Integrity, and Knowledge Check, and associated controls.
This interactive training course will ensure professionals and practitioners at all levels understand their roles and responsibilities, new developments, resources, and hallmarks of an effective compliance program. In this course, you will be asked to read through lessons, participate in learning activities, and partake in knowledge checks designed to reinforce learning, followed by the end of the course's final assessment.
For Corporate Request Demo →
What you will learn:
- By the end of this course, students will be able to:
- Understand the CMMC Model and controls
- Interpret the NIST SP 800-171 Controls and apply the control guidance in gap analysis, remediating and implementing controls
- Understand the specific domains:
- Personnel Security - Personnel Security requires organizations to screen individuals before authorizing access to systems containing CUI.
- Physical Protection - Limit physical access to organizational information systems.
- Risk Management - Assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals.
- Security Assessment - Evaluate the security posture of the organization, based on the ability to manage its cyber risk profile, identify its inherent risks, and assess the effectiveness of its controls environment.
- System & Communications Protection - Monitor, control and protect organizational communications
- System & Information Integrity - Adopt a broad range of security practices to protect information integrity.