System Security Plan
Acme Precision Machining
- CAGE code
- 1ABC2
- Company size
- 11-50 employees
- Industry
- Precision machining
- Scope
- Handles CUI (CMMC Level 2)
- Standard
- NIST SP 800-171 Rev 2
Acme machines aluminum brackets and housings for defense primes. It handles CUI on a small, segmented internal network managed by the owner and a part-time IT contractor.
AC — Access Control
3.1.1 Limit system access to authorized users, processes, and devices
ImplementedAcme Precision Machining assigns every user an individual account; shared logins are prohibited. Accounts are created on hire and disabled during offboarding as part of the company's departure checklist.
Questionnaire coverage: 3 of 3 assessment objectives answered
3.1.5 Employ the principle of least privilege
ImplementedAdministrative privileges are limited to the owner and the contracted IT provider. Production staff operate as standard users on the shop-floor systems.
Questionnaire coverage: 2 of 2 assessment objectives answered
3.1.8 Limit unsuccessful logon attempts
Planned (not implemented)Automatic account lockout after repeated failed sign-in attempts is not yet configured. This deficiency is tracked in the Plan of Action and Milestones (POA&M).
Questionnaire coverage: 1 of 1 assessment objective answered
IA — Identification and Authentication
3.5.1 Identify system users, processes, and devices
ImplementedEach user and managed device is uniquely identified before access to company systems is granted.
Questionnaire coverage: 2 of 2 assessment objectives answered
3.5.3 Use multifactor authentication
Partially implementedMultifactor authentication is enforced for email and remote access. It is not yet required for local privileged access to the CUI environment; closing that gap is tracked in the POA&M.
Questionnaire coverage: 2 of 2 assessment objectives answered · 1 flagged "I don't know"
SC — System and Communications Protection
3.13.1 Monitor, control, and protect communications at system boundaries
ImplementedA firewall segments the CUI environment from the guest and general office networks; inbound access is denied by default.
Questionnaire coverage: 2 of 2 assessment objectives answered
3.13.11 Employ FIPS-validated cryptography to protect CUI
Partially implementedEncryption protects CUI in transit and at rest, but the cryptographic modules in use are not yet FIPS-validated. Migrating to FIPS-validated modules is tracked in the POA&M.
Questionnaire coverage: 1 of 1 assessment objective answered