网络安全 Achieving Cmmc Level 2 Compliance

Model: minimax-m3 | ¥0.20/call
网络安全Claude Opus 4.7安全审计AchievingCmmc

Achieving Cmmc Level 2 Compliance:网络安全 skill: achieving-cmmc-level-2-compliance,适用于安全分析、取证与威胁排查场景。

Calls: 1

Skill Documentation

网络安全 Achieving Cmmc Level 2 Compliance

摘要

Achieving Cmmc Level 2 Compliance:网络安全 skill: achieving-cmmc-level-2-compliance,适用于安全分析、取证与威胁排查场景。

> 来源: mukul975/Anthropic-Cybersecurity-Skills (18k stars) — 网络安全专业技能集

> 原文件: skills/achieving-cmmc-level-2-compliance/SKILL.md

> 模型推荐: claude-opus-4-7 (安全分析深度推理)

这个 skill 是干嘛的

mukul975 整理的 100+ 个网络安全专业 skill,覆盖渗透测试 / 取证 / 威胁情报 / 合规审计 / 云安全 / 移动安全 等领域。每个 skill 对应一个具体的安全分析任务。

michael 强调"skill 要有相应的指导功能,指导用户使用",所以加了下面两节让 Agent 和用户对接。

---

🤖 Agent 使用说明

1. 用户提到"分析 X 日志 / 取证 / 检测威胁 / 渗透测试 / 安全审计"时,触发对应 skill

2. skill 会按操作步骤一步步执行(取证镜像 / 解析日志 / 跑威胁情报 / etc.)

3. 涉及破坏性操作(rm/drop/format)前必须 ask user 确认

4. 完工后让 Agent 跑自检 step

5. 如果用户要求做"防御性分析" — 区分恶意代码审计 vs 渗透测试

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 如果需要提供文件/镜像/日志/哈希,按 Agent 提示提供

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

原 skill 内容(mukul975/Anthropic-Cybersecurity-Skills/skills/achieving-cmmc-level-2-compliance/SKILL.md,截断到 12k chars)

---

name: achieving-cmmc-level-2-compliance

description: >-

Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI

and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14

families, compute the SPRS score with the DoD Assessment Methodology, manage a

compliant POA&M, and ready the organization for a C3PAO assessment. Use when an

organization handles Controlled Unclassified Information (CUI) under a DoD contract,

when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for

or responding to a CMMC assessment, when computing or improving an SPRS score, when

building a System Security Plan or POA&M for 800-171, or when scoping which systems

are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2,

CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment

Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.

domain: cybersecurity

subdomain: compliance-governance

tags:

version: "1.0"

author: andrewibrah

license: Apache-2.0

nist_csf:

mitre_attack:

---

Achieving CMMC Level 2 Compliance

When to Use

Prerequisites

Workflow

1. Determine applicability and CUI categories

Confirm the contract requires CMMC Level 2 (CUI present, not just FCI). FCI-only contracts are **Level 1** (the 15 FAR 52.204-21 requirements). Identify CUI categories from the contract and the DoD CUI Registry.

2. Scope the environment

Classify every asset into one of the CMMC scoping categories:

Minimize scope deliberately — a smaller, well-segmented CUI enclave is far cheaper to certify than a flat network.

3. Implement the 110 requirements (NIST SP 800-171 Rev 2)

Work the **14 families** (3.1–3.14). For each requirement, implement, then write the **how** in the SSP. High-leverage early wins: MFA (3.5.3), FIPS-validated cryptography (3.13.11), audit logging (3.3.x), access control + least privilege (3.1.x), and incident response (3.6.x).

4. Score with the DoD Assessment Methodology (SPRS)

Start at **110** and subtract the weighted value (**1, 3, or 5 points**) of each **unmet** requirement; partial credit applies to a small number of controls (e.g., MFA, FIPS crypto). The result is the **SPRS score** (maximum 110; the methodology floor is −203). Post the score, the SSP date, and the assessment scope to **SPRS** (or eMASS for higher assessments).

5. Build a compliant POA&M

Document every unmet requirement with owner, remediation, and milestone. **Constraints under the CMMC rule:** a **Conditional** status requires a score of at least **80%** (≥ 88 of 110), only **POA&M-eligible** requirements may be deferred (the highest-weighted security requirements must be fully met — verify eligibility against 32 CFR Part 170), and all POA&M items must be **closed within 180 days** to convert Conditional → **Final**.

6. Assess (self or C3PAO)

Assessors evaluate each objective as **MET / NOT MET / N/A** with evidence (examine/interview/test). A senior official files the **annual affirmation** of continued compliance.

7. Maintain certification

Certification is valid **three years** with **annual affirmations**. Maintain the SSP, re-score on change, keep evidence current, and feed significant changes back into the assessment.

Key Concepts

| Concept | Definition |

|---|---|

| FCI | Federal Contract Information — Level 1 protects it (FAR 52.204-21). |

| CUI | Controlled Unclassified Information — Level 2 protects it (NIST 800-171). |

| 110 requirements | The SP 800-171 Rev 2 security requirements across 14 families. |

| SPRS | Supplier Performance Risk System — where the 800-171 score is posted. |

| DoD Assessment Methodology | The 1/3/5-point weighting used to compute the score from 110. |

| C3PAO | CMMC Third-Party Assessment Organization — performs Level 2 certification. |

| POA&M | Plan of Action & Milestones — limited, must close in 180 days for Final status. |

| Conditional vs Final | Conditional = open POA&M (score ≥ 80%); Final = all controls met. |

| ESP | External Service Provider — must meet FedRAMP Moderate / equivalency for CUI. |

| Scoping categories | CUI / Security Protection / Contractor Risk Managed / Specialized / Out-of-Scope. |

Tools & Systems

Common Scenarios

Output Format

Produce a **CMMC Level 2 Readiness Report** using `assets/template.md`, containing:

1. **Applicability & CUI categories** — why Level 2 applies.

2. **Scope** — assets by scoping category and the CUI boundary diagram reference.

3. **Control status by family** — met / not met / N/A across the 14 families.

4. **SPRS score** — computed score, deductions, and the gap to 110 and to the 88 threshold.

5. **POA&M** — unmet requirements, eligibility check, owners, 180-day milestones.

6. **Assessment path** — self vs C3PAO, target date, affirmation owner.

7. **Remediation roadmap** — sequenced by point value and effort.

Use `scripts/process.py` to compute the SPRS score from a control-status JSON, flag POA&M-eligibility concerns, and report the gap to the conditional-certification threshold.

常见问题(FAQ)

使用「Achieving Cmmc」这个 skill 能解决什么问题?

本 skill 专注于Achieving Cmmc,网络安全 skill: achieving-cmmc-level-2-compliance。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Achieving Cmmc」?

当你需要在Achieving Cmmc Level 2 Compliance相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Achieving Cmmc」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。

FAQ

👤 用户需要做什么?

1. 告诉 Agent 你要做什么(分析日志 / 取证 / 安全审计 / 渗透测试)

2. 如果需要提供文件/镜像/日志/哈希,按 Agent 提示提供

3. 涉及破坏性操作时明确告诉 Agent"继续"或"取消"

4. 全程 Agent 自动化,你只需提供数据 + 回答决策点

---

使用「Achieving Cmmc」这个 skill 能解决什么问题?

本 skill 专注于Achieving Cmmc,网络安全 skill: achieving-cmmc-level-2-compliance。它将相关流程标准化,帮助用户更快拿到可靠结果,减少重复手工操作。

什么情况下适合使用「Achieving Cmmc」?

当你需要在Achieving Cmmc Level 2 Compliance相关工作中获得稳定、可复用的产出时最适合——无论是单次任务还是纳入日常工作流,都能直接调用。

使用「Achieving Cmmc」前需要准备什么?

需要明确授权范围内的目标系统或样本文件,并准备隔离的分析环境(虚拟机/沙箱)。