Register:Glossary3 recordsSHA3-256 chainedhead sha3:eaa3ad4e96b32e18eda1e5206a4615ad088b444ee548ca8b6af3d58c29613670Intact
REC 0001TERMSsha3-25621e1837a080d00f109a7c3c5fe73f0f44528914a513935291257dca6db607624prev:343b9e774a08

Terms

  1. CUIControlled Unclassified InformationCUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified.
  2. FCIFederal Contract InformationFCI is information provided by or generated for the government under a contract that is not intended for public release: the trigger for CMMC Level 1.
  3. SPRSSupplier Performance Risk SystemSPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations.
  4. C3PAOCMMC Third-Party Assessment OrganizationA C3PAO is an organization authorized by the Cyber AB to conduct official CMMC Level 2 certification assessments.
  5. NIST SP 800-171NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2.
  6. SSPSystem Security PlanAn SSP is the document describing how an organization implements each required security control across its in-scope environment.
  7. POA&MPlan of Action and MilestonesA POA&M is a tracked plan for remediating security controls that are not yet fully implemented, with owners and target dates.
  8. DIBCACDefense Industrial Base Cybersecurity Assessment CenterDIBCAC is the DoD organization that conducts government-led high assessments and CMMC Level 3 assessments.
  9. DFARS 252.204-7012DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours.
  10. CUI EnclaveA CUI enclave is a segmented, hardened environment that isolates CUI so only that boundary, not the whole company, falls in CMMC scope.
REC 0002RELATED RECORDSsha3-256eaa3ad4e96b32e18eda1e5206a4615ad088b444ee548ca8b6af3d58c29613670prev:21e1837a080d

Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

proof.state
Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
proof.change
Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
proof.agency
Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
architecture
Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Know the terms. Then see the records behind them.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000HEAD343b9e774a0804d8895b52d9
REC 0001TERMS21e1837a080d343b9e774a08
REC 0002RELATED RECORDSeaa3ad4e96b321e1837a080d

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:eaa3ad4e96b3. The product does the same thing to your evidence.