Notice2024-13468
Submission for OMB Review; Comment Request
Primary source
Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.
Published
June 21, 2024
Issuing agencies
Defense Department
Abstract
The DoD has submitted to the Office of Management and Budget (OMB) for clearance the following proposal for collection of information under the provisions of the Paperwork Reduction Act.
Full Text
<html>
<head>
<title>Federal Register, Volume 89 Issue 120 (Friday, June 21, 2024)</title>
</head>
<body><pre>
[Federal Register Volume 89, Number 120 (Friday, June 21, 2024)]
[Notices]
[Pages 52032-52033]
From the Federal Register Online via the Government Publishing Office [<a href="http://www.gpo.gov">www.gpo.gov</a>]
[FR Doc No: 2024-13468]
-----------------------------------------------------------------------
DEPARTMENT OF DEFENSE
Office of the Secretary
[Docket ID: DoD-2023-OS-0063]
Submission for OMB Review; Comment Request
AGENCY: Office of the Department of Defense Chief Information Officer
(CIO), Department of Defense (DoD).
ACTION: 30-Day information collection notice.
-----------------------------------------------------------------------
SUMMARY: The DoD has submitted to the Office of Management and Budget
(OMB) for clearance the following proposal for collection of
information under the provisions of the Paperwork Reduction Act.
DATES: Consideration will be given to all comments received by July 22,
2024.
ADDRESSES: Written comments and recommendations for the proposed
information collection should be sent within 30 days of publication of
this notice to <a href="http://www.reginfo.gov/public/do/PRAMain">www.reginfo.gov/public/do/PRAMain</a>. Find this particular
information collection by selecting ``Currently under 30-day Review--
Open for Public Comments'' or by using the search function.
FOR FURTHER INFORMATION CONTACT: Reginald Lucas, (571) 372-7574,
<a href="/cdn-cgi/l/email-protection#cbbca3b8e5a6a8e6aaa7aeb3e5aeb8afe5a6a9b3e5afafe6afa4afe6a2a5ada4b9a6aabfa2a4a5e6a8a4a7a7aea8bfa2a4a5b88ba6aaa2a7e5a6a2a7"><span class="__cf_email__" data-cfemail="d7a0bfa4f9bab4fab6bbb2aff9b2a4b3f9bab5aff9b3b3fab3b8b3fabeb9b1b8a5bab6a3beb8b9fab4b8bbbbb2b4a3beb8b9a497bab6bebbf9babebb">[email protected]</span></a>.
SUPPLEMENTARY INFORMATION:
Title; Associated Form; and OMB Number: Cybersecurity Maturity
Model Certification (CMMC) Enterprise Mission Assurance Support-Service
(eMASS) Instantiation Information Collection; OMB Control Number 0704-
0676.
Type of Request: New.
Accreditation Body Submission of C3PAO Information in eMASS
Number of Respondents: 1.
Responses per Respondent: 240.
Annual Responses: 240.
Average Burden per Response: 5 minutes.
Annual Burden Hours: 20.
C3PAO Submission of Assessment Data and Results in eMASS
Number of Respondents: 10,942.
Responses per Respondent: 1.
Annual Responses: 10,942.
Average Burden per Response: 15 minutes.
Annual Burden Hours: 2,735.5.
Total
Number of Respondents: 10,943.
Annual Responses: 11,182.
Annual Burden Hours: 2,756.
Needs and Uses: The CMMC Program provides for the assessment of
contractor implementation of cybersecurity requirements to enhance
confidence in contractor protection of unclassified information within
the DoD supply chain. CMMC contractual requirements are implemented
under a Title 48 acquisition rule, with associated rulemaking for the
CMMC Program requirements (e.g., CMMC Scoring Methodology, certificate
issuance, information accessibility) under a Title 32 program rule (32
Code of Federal Regulations (CFR) Part 170). The CMMC Title 32 program
rule includes two separate information collection requests (ICR), one
for the CMMC Program and this one for CMMC eMASS.
The CMMC instantiation of eMASS is the electronic collection
mechanism for collecting CMMC program data, which provides the
Department of Defense (DoD) visibility of the CMMC Levels 2 and 3
certification assessment results.
This information collection is necessary to support the
implementation of the CMMC assessment process for CMMC Level 2 and
Level 3 certification assessments, as
[[Page 52033]]
defined in 32 CFR 170.17 and 170.18 respectively.
The CMMC Level 2 certification assessment process is conducted by
Certified Assessors, employed by CMMC Third-Party Assessment
Organizations (C3PAOs). During the assessment process, Organizations
Seeking Certification's hire C3PAOs to conduct the third-party
assessment required for certification. The CMMC Certified Assessors
upload assessment data: pre-assessment and planning material (date and
level of the assessment; C3PAO name and unique identifier; name and
business contact information for each Assessor; all industry CAGE codes
associated with the information systems addressed by the CMMC
Assessment Scope; name, date, and version of the system security plan
(SSP); the Title 32 program rule (32 CFR part 170)), final assessment
reports (assessment result for each requirement objective; POA&M usage
and compliance, as applicable; and list of artifact names, the return
values of the hashing algorithm, and the hashing algorithm used), and
appropriate CMMC certificates of assessment (certification date, as
applicable) into the CMMC instantiation of eMASS.
The CMMC Level 3 certification assessment process is conducted by
the Defense Contract Management Agency (DCMA) Defense Industrial Base
Cybersecurity Assessment Center (DIBCAC). DCMA DIBCAC assessors upload
assessment data: pre-assessment and planning material (date and level
of the assessment; name and business contact information for each
Assessor; all industry CAGE codes associated with the information
systems addressed by the CMMC Assessment Scope; name, date, and version
of the system security plan (SSP); the Title 32 program rule (32 CFR
part 170)), final assessment reports (assessment result for each
requirement objective; POA&M usage and compliance, as applicable; and
list of artifact names, the return values of the hashing algorithm, and
the hashing algorithm used), and appropriate CMMC certificates of
assessment (certification date, as applicable) into the CMMC
instantiation of eMASS.
The Accreditation Body provides the CMMC Program Management Office
with current data on C3PAOs and Assessors, including authorization and
accreditation records and status using the CMMC instantiation of eMASS.
Affected Public: Business or other for-profit.
Frequency: On occasion.
Respondent's Obligation: Voluntary.
OMB Desk Officer: Ms. Jasmeet Seehra.
You may also submit comments and recommendations, identified by
Docket ID number and title, by the following method:
<bullet> Federal eRulemaking Portal: <a href="http://www.regulations.gov">http://www.regulations.gov</a>.
Follow the instructions for submitting comments.
Instructions: All submissions received must include the agency
name, Docket ID number, and title for this Federal Register document.
The general policy for comments and other submissions from members of
the public is to make these submissions available for public viewing on
the internet at <a href="http://www.regulations.gov">http://www.regulations.gov</a> as they are received without
change, including any personal identifiers or contact information.
DoD Clearance Officer: Mr. Reginald Lucas.
Requests for copies of the information collection proposal should
be sent to Mr. Lucas at <a href="/cdn-cgi/l/email-protection#b3c4dbc09dded09ed2dfd6cb9dd6c0d79dded1cb9dd7d79ed7dcd79edaddd5dcc1ded2c7dadcdd9ed0dcdfdfd6d0c7dadcddc0f3ded2dadf9ddedadf"><span class="__cf_email__" data-cfemail="8ff8e7fca1e2eca2eee3eaf7a1eafceba1e2edf7a1ebeba2ebe0eba2e6e1e9e0fde2eefbe6e0e1a2ece0e3e3eaecfbe6e0e1fccfe2eee6e3a1e2e6e3">[email protected]</span></a>.
Dated: June 14, 2024.
Aaron T. Siegel,
Alternate OSD Federal Register Liaison Officer, Department of Defense.
[FR Doc. 2024-13468 Filed 6-20-24; 8:45 am]
BILLING CODE 6001-FR-P
</pre><script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script></body>
</html>Indexed from Federal Register on June 21, 2024.
This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.