CMMC-CCA Web TestEngine demo

Exit VCEDump CMMC-CCA Certified CMMC Assessor (CCA)
Question 45 of 80
0% complete
Q45 Single choice

While conducting a CMMC Level 2 Third-Party Assessment of a small defense contractor, an assessor discovers that the contractor's Information Security Policy has no documented change records demonstrating executive approval. The IT director states that they will add change records in the future, but that other evidence exists.

Which documentation is MOST able to demonstrate persistent and habitual adherence to CMMC requirements?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in