SIEM (Security Information and Event Management)
A cybersecurity tool that collects, correlates, and analyzes log data from across an organization’s systems to detect suspicious activity. SIEM platforms provide real-time visibility into potential threats, generate alerts, and support incident response and compliance reporting. In the context of CMMC, SIEM helps organizations monitor their environments and demonstrate active security operations.
Encryption
The process of converting readable data into an encoded format that can only be accessed by someone with the correct decryption key. Encryption ensures that sensitive information, such as CUI, remains secure in transit (data traveling over networks) and at rest (data stored on devices or servers). It is a core requirement under NIST SP […]
Multi-Factor Authentication (MFA)
A layered security control requiring users to provide at least two distinct methods of verification before accessing systems or data. Common factors include something you know (a password), something you have (a phone or token), and something you are (biometrics). MFA dramatically reduces the risk of unauthorized access, even if one factor—such as a password—is […]
Incident Response Plan (IRP)
A documented strategy that defines how an organization prepares for, detects, responds to, and recovers from cybersecurity incidents. A strong IRP outlines roles and responsibilities, communication protocols, containment steps, evidence preservation, and post-incident reviews. It ensures organizations can act quickly and effectively to minimize damage, meet reporting requirements, and strengthen defenses after an incident.
Advanced Persistent Threat (APT)
A sophisticated and sustained cyberattack, often carried out by nation-state actors or well-resourced adversaries. APTs aim to infiltrate systems and remain undetected for long periods, stealing sensitive data such as defense designs, intellectual property, or government information. CMMC was developed in part to ensure contractors handling CUI can defend against threats at this level.
Accreditation Body (Cyber AB)
The official nonprofit entity designated by the Department of Defense to manage the CMMC ecosystem. The Cyber AB develops assessment standards, accredits C3PAOs, trains Certified CMMC Professionals (CCPs) and Certified CMMC Assessors (CCAs), and ensures the integrity of the certification process. It acts as the governing authority that connects industry with the DoD’s compliance expectations.
DIBCAC (Defense Industrial Base Cybersecurity Assessment Center)
A specialized DoD unit responsible for conducting high-level assessments of contractors’ compliance with cybersecurity requirements, including NIST SP 800-171 and CMMC. DIBCAC assessments are considered the gold standard and are often performed on large or high-risk defense contractors. Their evaluations help set the benchmark for cybersecurity readiness within the Defense Industrial Base.
Defense Industrial Base (DIB)
The broad community of companies, organizations, and subcontractors that provide goods and services to the Department of Defense. The DIB spans manufacturers, technology providers, logistics companies, and professional services firms. Because of its size and critical role in national defense, the DIB is a frequent target for cyberattacks, making strong cybersecurity practices essential across the […]
Self-Assessment
An internal evaluation performed by contractors to measure compliance with NIST SP 800-171 requirements and, in some cases, CMMC Level 1. Self-assessments are scored using the DoD’s Supplier Performance Risk System (SPRS), where contractors submit their results. While self-assessments provide a baseline, only third-party or government assessments can validate certification for contracts requiring CMMC Level […]
C3PAO (Certified Third-Party Assessment Organization)
An independent organization authorized by the Cyber AB and approved by the Department of Defense to conduct official CMMC assessments. C3PAOs evaluate whether contractors have implemented the necessary practices and processes at the required maturity level, most notably for Level 2 certifications. Only C3PAO assessments uploaded to the DoD’s Supplier Performance Risk System (SPRS) are […]