Frameworks / CMMC 2.0 / CA.L2-3.12.3 What else in your programme already covers this This control maps to 88 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
10.2.1 10.2.1 Audit logging enabled on all system components 10.4.1 10.4.1 Daily review of security-relevant logs 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 10.7.2 10.7.2 Detect and alert on critical security control failures 11.3.2.1 11.3.2.1 External scans after significant change 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 12.3.4 12.3.4 Annual review of hardware and software technologies 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.8.4 12.8.4 Annual monitoring of TPSP compliance status 2.2.1 2.2.1 System configuration standards maintained 6.4.1 6.4.1 Public web application review or automated protection 6.3.1 6.3.1 Vulnerability identification and risk ranking NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring CIS-13.1 Centralize Security Event Alerting CIS-13.6 Collect Network Traffic Flow Logs CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-18.4 Validate Security Measures CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-8.9 Centralize Audit Logs SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SEC01-BP03 Identify and validate control objectives SEC01-BP06 Automate deployment of standard security controls SEC04-BP04 Initiate remediation for non-compliant resources ASBv3-PV-4 Audit and enforce secure configurations for compute resources PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments 10.1 Nonconformity and corrective action 9.1 Monitoring, measurement, analysis and evaluation 9.2.2 Audit programme(s) 5.36 Compliance with policies, rules and standards for information security 7.4 Physical security monitoring 8.16 Monitoring activities CPS234-22 Systematic Control Testing Program CPS234-P17 Active Maintenance of Capability Against Change C5-COM-04 Information on information security performance and management assessment of the ISMS C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) 5.36 Compliance with policies, rules and standards for information security 8.9 Configuration management 5.7.1 Monitoring, measurement, analysis and evaluation 6.15.2 Information security reviews 3.11.5e Assess Effectiveness of Security Solutions 3.14.2e Monitor Organizational Systems with Specialized Capabilities E8-PATCHOS-ML2 Patch Operating Systems (ML2) ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions CPS220-P48 Assessment Following Material Change Outside the Review Cycle CPS230-P30 Monitoring, Review and Testing of Control Effectiveness SPS220-P28 Annual Review in Non Comprehensive Review Years ASD37-28 Continuous incident detection and response (Excellent) AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program AEO-13 Measurement, Analyses and Improvement CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems 9.1 Monitoring, measurement, analysis and evaluation Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures 53A-F Ongoing Assessment and Automation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Security Assessment You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 CA.L2-3.12.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.