Câu 15: CCA: CMMC Certified Assessor
While examining the customer responsibility matrix submitted by the OSC for one of its Cloud Service Providers (CSPs), the Assessor notes that the matrix was substantially completed by the OSC’s RPO. In fact, there is a statement from the RPO that the CSP has met the requirements for FedRAMP MODERATE. In order to acce…
Nội dung câu hỏi
While examining the customer responsibility matrix submitted by the OSC for one of its Cloud Service Providers (CSPs), the Assessor notes that the matrix was substantially completed by the OSC’s RPO. In fact, there is a statement from the RPO that the CSP has met the requirements for FedRAMP MODERATE. In order to accept that this CSP is in fact, qualified to perform some of the practices on behalf of the OSC, what should occur?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. The OSC should provide the contract documents for the CSP specifying that it must meet NIST SP 800-171 practices.
- B. The CSP must have its service certified for FedRAMP by a certified C3PAO.
- C. The OSC must be able to demonstrate that the CSP is providing its services in a manner that complies with CMMC Level 2.
- D. There must be other evidence that an independent firm has confirmed the security controls meeting FedRAMP MODERATE are in place for the CSP. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.