Frameworks / CMMC 2.0 / RA.L2-3.11.2 What else in your programme already covers this This control maps to 77 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 1.2.6 Security features for insecure services in use 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.3.1.3 11.3.1.3 Internal scans after significant change 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.3.2.1 11.3.2.1 External scans after significant change 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.3 11.4.3 External penetration testing annually and after change 11.4.5 11.4.5 Annual segmentation penetration testing 2.2.1 2.2.1 System configuration standards maintained 6.4.1 6.4.1 Public web application review or automated protection 5.2.1 5.2.1 Anti-malware deployed on all system components 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 6.3.3 6.3.3 Timely installation of security patches CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-16.13 Conduct Application Penetration Testing CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-18.2 Perform Periodic External Penetration Tests CIS-18.5 Perform Periodic Internal Penetration Tests CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-7.7 Remediate Detected Vulnerabilities SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SEC06-BP01 Perform vulnerability management SEC11-BP02 Automate testing throughout the development and release lifecycle SEC11-BP03 Perform regular penetration testing C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-22 Testing and Documentation of known Vulnerabilities C5-PSS-02 Identification of Vulnerabilities of the Cloud Service RA-5 Vulnerability Monitoring and Scanning RA-5(2) Update Vulnerabilities to be Scanned RA-5(5) Privileged Access RA-5 Vulnerability Monitoring and Scanning RA-5(2) Update Vulnerabilities to be Scanned RA-5(5) Privileged Access NIST800-PM-31 PM-31 Continuous Monitoring Strategy NIST800-RA-5 RA-5 Vulnerability Monitoring and Scanning SP800-53-RA Risk Assessment Family E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHOS-ML1 Patch Operating Systems (ML1) CPS234-22 Systematic Control Testing Program CPS234-P17 Active Maintenance of Capability Against Change ASD37-02 Patch applications (Essential) ASD37-19 Patch operating systems (Essential) DS-2 Ensure software supply chain security PV-5 Perform vulnerability assessments ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions AUCDR-IS-4 Formal vulnerability management program 8.8 Management of technical vulnerabilities 8.8 Management of technical vulnerabilities 6.9.6 Technical vulnerability management 9.1 Monitoring, measurement, analysis and evaluation 03.11.02 Vulnerability Monitoring and Scanning 3.12.1e Penetration Testing by Independent Agents Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Risk Assessment You are reading one control. How much of CMMC 2.0 have you already done? CMMC 2.0 RA.L2-3.11.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.
Query this from an agent The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.