-
Define the Level 2 assessment boundary and trace CUI across systems, users, facilities, and providers.
-
Categorize CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets.
-
Build an assessment plan for all 110 Level 2 requirements and their applicable assessment objectives.
-
Select and perform appropriate examine, interview, and test activities.
-
Determine whether evidence is relevant, current, complete, and sufficient.
-
Record MET and NOT MET findings, calculate the score, and evaluate POA&M eligibility.
-
Prepare results for SPRS submission, affirmation, and continuing compliance.