Skip to content

Commit bb8d04a

Browse files
authored
Merge pull request #193710 from timwarner-msft/patch-12
Add clarification to CMMC Levels
2 parents 90221e4 + 94b0840 commit bb8d04a

File tree

1 file changed

+7
-4
lines changed

1 file changed

+7
-4
lines changed

articles/governance/policy/samples/cmmc-l3.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
---
22
title: Regulatory Compliance details for CMMC Level 3
33
description: Details of the CMMC Level 3 Regulatory Compliance built-in initiative. Each control is mapped to one or more Azure Policy definitions that assist with assessment.
4-
ms.date: 03/14/2022
4+
ms.date: 04/01/2022
55
ms.topic: sample
66
ms.custom: generated
77
---
88
# Details of the CMMC Level 3 Regulatory Compliance built-in initiative
99

1010
The following article details how the Azure Policy Regulatory Compliance built-in initiative
11-
definition maps to **compliance domains** and **controls** in CMMC Level 3.
11+
definition maps to **compliance domains** and **controls** in Cybersecurity Maturity Model Certification (CMMC) Level 3.
1212
For more information about this compliance standard, see
1313
[CMMC Level 3](https://www.acq.osd.mil/cmmc/documentation.html). To understand
1414
_Ownership_, see [Azure Policy policy definition](../concepts/definition-structure.md#type) and
@@ -22,6 +22,9 @@ Then, find and select the **CMMC Level 3** Regulatory Compliance built-in
2222
initiative definition.
2323

2424
> [!IMPORTANT]
25+
> This policy initiative was built to CMMC version 1.0 and will be updated in the future".
26+
> CMMC Level 2 under CMMC 2.0 is similar to CMMC Level 3 under CMMC 1.0, but has different control mappings.
27+
>
2528
> Each control below is associated with one or more [Azure Policy](../overview.md) definitions.
2629
> These policies may help you [assess compliance](../how-to/get-compliance-data.md) with the
2730
> control; however, there often is not a one-to-one or complete match between a control and one or
@@ -31,7 +34,7 @@ initiative definition.
3134
> definitions at this time. Therefore, compliance in Azure Policy is only a partial view of your
3235
> overall compliance status. The associations between compliance domains, controls, and Azure Policy
3336
> definitions for this compliance standard may change over time. To view the change history, see the
34-
> [GitHub Commit History](https://github.com/Azure/azure-policy/commits/master/built-in-policies/policySetDefinitions/Regulatory%20Compliance/CMMC_L3.json).
37+
> [GitHub commit history](https://github.com/Azure/azure-policy/commits/master/built-in-policies/policySetDefinitions/Regulatory%20Compliance/CMMC_L3.json).
3538
3639
## Access Control
3740

@@ -1097,4 +1100,4 @@ Additional articles about Azure Policy:
10971100
- See the [initiative definition structure](../concepts/initiative-definition-structure.md).
10981101
- Review other examples at [Azure Policy samples](./index.md).
10991102
- Review [Understanding policy effects](../concepts/effects.md).
1100-
- Learn how to [remediate non-compliant resources](../how-to/remediate-resources.md).
1103+
- Learn how to [remediate non-compliant resources](../how-to/remediate-resources.md).

0 commit comments

Comments
 (0)