CMMC Level 2 Requirements and the AIC Level 2 Kit
Cybersecurity Maturity Model Certification (CMMC) Level 2 protects Controlled Unclassified Information (CUI) with the 110 security requirements in National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 2. The Analog Informatics Corporation (AIC) Level 2 kit includes every Level 1 module, plus Privileged Identity Management, Privileged Access Management, Privileged User Management, Identity Governance and Administration, Audit, training and attestation, Secure Application Launch, Jump, command restriction, Incident Response, and validated cryptography.
How to read the kit role
| Kit role | Meaning |
|---|---|
| Performs | On the systems and paths the kit manages, the named feature carries out the requirement. |
| Assists | The feature supplies the tool, workflow, or record. People carry out the requirement. |
| Records | The work is physical, personnel, or policy work. The Assessment Binder stores the organization's record. |
Feature names used in the tables
The tables name the kit feature that does the work. Short names used below:
- Privileged Identity Management (PIM): vaulted privileged credentials with checkout, rotation, and propagation.
- Privileged Access Management (PAM): brokered Secure Shell (SSH), Remote Desktop Protocol (RDP), and Virtual Network Computing (VNC) sessions in the browser, with approvals and command restriction.
- Privileged User Management (PUM): just-in-time elevation on Windows, Mac, and Linux endpoints, with approvals and signed grants.
- Identity Governance and Administration (IGA): account lifecycle and access review for kit accounts.
- Role-based access control (RBAC): permission checks on every console page and interface.
- Multi-factor authentication (MFA): a password plus a second step.
- Security Information and Event Management (SIEM): the organization's log collector.
- Plan of Action and Milestones (POA&M) and system security plan (SSP): assessment documents the Assessment Binder supports.
- Security Technical Implementation Guide (STIG): a published configuration baseline.
- Federal Contract Information (FCI) and Controlled Unclassified Information (CUI): the information each level protects.
- Current State Compliance: the console page that lists control findings and runs Rescan.
- Configuration compliance: checks of each enrolled system against its approved baseline configuration.
- Transport Layer Security (TLS): encryption for data moving across the network.
- Advanced Encryption Standard (AES-256, AES-256-GCM): encryption for stored data.
- Password-Based Key Derivation Function 2 (PBKDF2): the one-way hash used to store local passwords.
- Lightweight Directory Access Protocol (LDAP) and Security Assertion Markup Language (SAML 2.0): directory and single sign-on standards the kit connects to.
- Amazon Web Services LibCrypto (AWS-LC): the cryptographic module the server uses. It holds a Federal Information Processing Standards (FIPS) 140-3 certificate.
- Hardware Security Module (HSM): a device that holds encryption keys.
- Common Event Format (CEF) and Log Event Extended Format (LEEF): log formats SIEM products read.
- Coordinated Universal Time (UTC): the time standard on every audit record.
- Endpoint Detection and Response (EDR): antimalware software that also detects attacks.
- Virtual Private Network (VPN): an encrypted network connection into the organization.
- Defense Federal Acquisition Regulation Supplement (DFARS): the defense contract rules that set incident reporting.
- Fix-It: the console action that repairs a known setting on an enrolled system.
- Jump: the isolated access server that privileged sessions pass through.
All 110 Level 2 requirements
Jump to a family: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity.
Access Control (AC)
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| AC.L2-3.1.1 | Authorized Access Control | Performs | Only people with a kit account and an assigned role can sign in, with MFA. RBAC checks every console page and interface. PIM releases a vaulted privileged password only to an approved user, and PAM connects that user only to an approved target. Vault documents open only for named users. | Grant and remove access on systems the kit does not manage. |
| AC.L2-3.1.2 | Transaction & Function Control | Performs | Each role allows only its assigned console functions. PAM approval policies set which systems and protocols each user reaches. Command restriction blocks a disallowed command as it is typed. Secure Application Launch starts only approved applications. | Define the functions each role needs. |
| AC.L2-3.1.3 | Control CUI Flow | Performs | Data classification marks FCI and CUI, checks each person's clearance before release, and records every release. The document sharing vault and governed mail keep CUI on kit paths. | Control the flow of CUI on systems outside the kit. |
| AC.L2-3.1.4 | Separation of Duties | Assists | Administrator, approver, auditor, and user are separate roles, and privileged access goes through an approval workflow. IGA access review shows who holds each role. | Decide which duties must be separated, and assign people to roles. |
| AC.L2-3.1.5 | Least Privilege | Performs | PUM grants administrator rights for one task and removes them afterward, so users keep no standing administrator rights. PIM checks out privileged passwords for a limited time and rotates them. PAM approvals expire. | Apply least privilege on systems the kit does not manage. |
| AC.L2-3.1.6 | Non-Privileged Account Use | Performs | Privileged accounts live in the PIM vault. People sign in with their own everyday identity and check out a privileged account, or request elevation, only when a task needs it. | Issue separate everyday accounts on systems outside the kit. |
| AC.L2-3.1.7 | Privileged Functions | Performs | PUM stops a non-privileged user from running a privileged function until a request is approved and a signed grant is issued. Every privileged action is written to the audit log with the person's name. | Review privileged activity on schedule. |
| AC.L2-3.1.8 | Unsuccessful Logon Attempts | Performs | The console locks an account after repeated failed sign-ins. Conditional access and threat feeds block sign-in attempts from denied locations and known bad addresses. | Set lockout on systems outside the kit. |
| AC.L2-3.1.9 | Privacy & Security Notices | Records | A logon banner for every managed host is planned. Today the Assessment Binder stores the banner text and where it is set. | Set logon banners on each system. |
| AC.L2-3.1.10 | Session Lock | Assists | Console sessions end after an idle timeout. | Set a pattern-hiding screen lock on each workstation. |
| AC.L2-3.1.11 | Session Termination | Performs | Sessions end at an idle timeout and at an absolute time limit. Signing out revokes the session on the server, so its token cannot be reused. | Set session termination on other systems. |
| AC.L2-3.1.12 | Control Remote Access | Performs | PAM brokers SSH, RDP, and VNC sessions in the browser, so privileged remote access takes one approved, audited path. Conditional access checks country, network address, and MFA before the session starts. | Control remote access through the organization's VPN and other paths. |
| AC.L2-3.1.13 | Remote Access Confidentiality | Performs | Console, Agent, and session traffic is encrypted with TLS through AWS-LC, which holds a FIPS 140-3 certificate. | Encrypt remote access paths outside the kit. |
| AC.L2-3.1.14 | Remote Access Routing | Assists | When Jump is deployed, privileged remote sessions route through it as the managed access point. | Route all other remote access through managed access points. |
| AC.L2-3.1.15 | Privileged Remote Access | Performs | Each PAM session needs approval before it starts. PUM elevation needs approval and a signed grant. Command restriction blocks disallowed SSH commands as they are typed. | Authorize privileged remote access on other paths. |
| AC.L2-3.1.16 | Wireless Access Authorization | Records | The Assessment Binder stores the organization's record. | Authorize wireless access before connections are allowed. |
| AC.L2-3.1.17 | Wireless Access Protection | Records | The Assessment Binder stores the organization's record. | Protect wireless access with authentication and encryption. |
| AC.L2-3.1.18 | Mobile Device Connection | Records | The Assessment Binder stores the organization's record. | Control the connection of mobile devices. |
| AC.L2-3.1.19 | Encrypt CUI on Mobile | Assists | CUI stored in the kit is encrypted with AES-256. | Encrypt the storage of phones and laptops. |
| AC.L2-3.1.20 | External Connections | Performs | Configuration compliance checks each connecting system and can block one that fails. Data classification limits release of CUI on kit paths. | Approve and document external connections. |
| AC.L2-3.1.21 | Portable Storage Use | Records | The Assessment Binder stores the organization's record. | Limit portable storage on external systems. |
| AC.L2-3.1.22 | Control Public Information | Records | The Assessment Binder stores the organization's record. | Review and approve what is posted on public systems. |
Awareness and Training (AT)
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| AT.L2-3.2.1 | Role-Based Risk Awareness | Assists | Training and attestation assigns security awareness material from 53 ready-made templates to named people, sends reminders, and stores each signed attestation. Completion reports show who is done. | Choose content that fits the environment. |
| AT.L2-3.2.2 | Role-Based Training | Assists | The kit assigns templates to the named people in each role, with due dates, reminders, and completion reports. | Design the role-based training. |
| AT.L2-3.2.3 | Insider Threat Awareness | Assists | The Insider Threat Awareness template is assigned to named people, and each signed attestation is stored. | Run the insider threat program. |
Audit and Accountability (AU)
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| AU.L2-3.3.1 | System Auditing | Performs | The kit writes audit records for sign-in, access, elevation, sessions, configuration changes, and secret actions. Records go to the Windows Event Log and, as syslog in RFC 5424, CEF, or LEEF format, to your SIEM. | Set retention, and log systems outside the kit. |
| AU.L2-3.3.2 | User Accountability | Performs | Each record names the person, the action, the target, the outcome, and a request ID, so every action traces to one individual. | Use named accounts on other systems. |
| AU.L2-3.3.3 | Event Review | Assists | Audit event selection and SIEM forwarding settings let you change which events are logged after each review. | Review which events are logged. |
| AU.L2-3.3.4 | Audit Failure Alerting | Performs | The kit alerts when the audit or forwarding pipeline fails. | Respond to the alert. |
| AU.L2-3.3.5 | Audit Correlation | Assists | A request ID links related records, and forwarding sends them to your SIEM for correlation. The attack report maps blocked attacks to MITRE ATT&CK. | Correlate all sources in the SIEM. |
| AU.L2-3.3.6 | Reduction & Reporting | Assists | Audit search, filters, and export reduce records to what a review needs. The Assessment Binder produces reports. | Report on sources outside the kit. |
| AU.L2-3.3.7 | Authoritative Time Source | Assists | The server stamps every record in UTC and warns when a clock drifts. | Run the authoritative time source. |
| AU.L2-3.3.8 | Audit Protection | Performs | Audit records are insert-only, so they cannot be edited in place. Audit exports are hash-chained, so a changed record is detectable. | Protect copies in the SIEM and archive. |
| AU.L2-3.3.9 | Audit Management | Performs | Only authorized roles can view or export audit records. | Limit audit management on other systems. |
Configuration Management (CM)
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| CM.L2-3.4.1 | System Baselining | Assists | Configuration compliance holds a STIG-oriented baseline for each enrolled system and keeps an inventory of enrolled systems. | Set baselines and keep inventory for systems outside the kit. |
| CM.L2-3.4.2 | Security Configuration Enforcement | Performs | Configuration compliance checks each setting against the baseline. Fix-It repairs known settings. Findings the kit cannot repair are flagged for IT. | Fix the flagged findings. |
| CM.L2-3.4.3 | System Change Management | Assists | Kit setting changes are audited with the person's name. Current State Compliance records drift between scans, so an unapproved change shows up. | Run change approval. |
| CM.L2-3.4.4 | Security Impact Analysis | Assists | Current State Compliance Rescan shows the effect of a change on each control. | Analyze security impact before each change. |
| CM.L2-3.4.5 | Access Restrictions for Change | Performs | Only authorized roles can change kit settings, and each change is audited. | Restrict changes on other systems. |
| CM.L2-3.4.6 | Least Functionality | Assists | Configuration compliance flags settings outside the baseline. Secure Application Launch starts only approved applications. | Decide which functions are essential. |
| CM.L2-3.4.7 | Nonessential Functionality | Assists | Configuration compliance flags services that are not in the baseline. | Remove or disable nonessential programs, ports, and services. |
| CM.L2-3.4.8 | Application Execution Policy | Records | The Assessment Binder stores the organization's record. | Set the application allow or deny policy. |
| CM.L2-3.4.9 | User-Installed Software | Records | The Assessment Binder stores the organization's record. | Control and monitor user-installed software. |
Identification and Authentication (IA)
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| IA.L2-3.5.1 | Identification | Performs | People come from your directory as named users. Each enrolled system has its own Agent identity. Vaulted accounts are inventoried. | Identify users and devices on other systems. |
| IA.L2-3.5.2 | Authentication | Performs | Sign-in goes through Active Directory, LDAP, Microsoft Entra ID, Okta, Ping Identity, OpenID Connect, or SAML 2.0. Local passwords are stored as PBKDF2 hashes. | Authenticate users on other systems. |
| IA.L2-3.5.3 | Multifactor Authentication | Performs | Console sign-in requires MFA. PAM sessions and PUM requests start from that sign-in, so privileged access always passes MFA. | Require MFA for network access to other systems. |
| IA.L2-3.5.4 | Replay-Resistant Authentication | Performs | One-time codes and per-session tokens cannot be replayed, and every kit path uses TLS. | Use replay-resistant sign-in on other systems. |
| IA.L2-3.5.5 | Identifier Reuse | Assists | Each person keeps one durable identity record in the kit, so an identifier is not handed to someone else. | Prevent identifier reuse in the directory. |
| IA.L2-3.5.6 | Identifier Handling | Assists | IGA lifecycle and access review show inactive kit accounts so they can be disabled. | Disable inactive identities in the identity provider. |
| IA.L2-3.5.7 | Password Complexity | Performs | PIM generates rotated passwords that meet your complexity policy. Local console passwords must meet a complexity rule. | Set complexity on other systems. |
| IA.L2-3.5.8 | Password Reuse | Performs | Password history blocks reuse of rotated passwords and local console passwords. | Set password history on other systems. |
| IA.L2-3.5.9 | Temporary Passwords | Assists | PIM rotates managed account passwords on a schedule, so a shared temporary password does not last. | Force temporary password changes on other systems. |
| IA.L2-3.5.10 | Cryptographically-Protected Passwords | Performs | Passwords are stored as PBKDF2 hashes, vaulted secrets are encrypted with AES-256, and passwords travel only over TLS. | Protect passwords on other systems. |
| IA.L2-3.5.11 | Obscure Feedback | Performs | Password fields are masked, and a failed sign-in returns one generic message that does not say which part was wrong. | Obscure feedback on other systems. |
Incident Response (IR)
| Requirement | CMMC short name | Kit role | How the kit meets or supports it | What the organization does by hand |
|---|---|---|---|---|
| IR.L2-3.6.1 | Incident Handling | Assists | Incident Response records each incident, runs detections, and alerts the right people by email, text message, and ticket. | Staff the response team and run each incident. |
| IR.L2-3.6.2 | Incident Reporting | Assists | Incident records keep status and history, and they forward to ticket systems and the SIEM. | Report incidents to the Department of Defense as DFARS 252.204-7012 requires. |
| IR.L2-3.6.3 | Incident Response Testing | Assists | Incident Response records can hold the results of tests and tabletop exercises. | Run tests and tabletop exercises. |