Guide

Evidence, logging, access, and where the data lives.

Table 3 tells the organization to document Security Protection Assets in the inventory, the system security plan, and the network diagram, and to be ready for an assessment of the requirements that fit the capability. The notes below are how to collect that evidence from a vendor without treating a brochure as the record.

Not legal advice. This is a plain-language reading aid for contractors and the providers who support them. It is not a CMMC assessment, not a FedRAMP determination, and not a substitute for 32 CFR Part 170, the contract, or advice from counsel. Templates and worksheet results are starters. Replace every example with your own facts.

Shared responsibility

Section 170.19 says the use of an external service provider, the relationship, and the services go in the system security plan, and that the provider’s service description and customer responsibility matrix describe who does what.

Ask for that matrix, or build one from the answers and mark it as yours. The starter matrix is a list of topics, not a completed split. An SPA is assessed on the requirements relevant to its capability, so the matrix should not assign every Level 2 requirement to the vendor by default.

Logging

Logs are one of the Scoping Guide’s examples of security protection data. Ask which logs you can export, whether the log line can contain CUI, how long the vendor keeps them, and whether you can forward a copy to a system you operate.

If a log line contains CUI, the “security protection data without CUI” cell is the wrong cell. Say so in the inventory.

Access control

Record who can administer the service: your staff, the vendor’s staff, or both. Ask whether vendor access is standing or opened per request, whether you can use your own identity provider, and how privileged access is approved and revoked.

The Scoping Guide’s people examples exist because the person who maintains the control can be part of the asset story. Name the roles in the plan. Do not stop at the product name.

Where the data lives

Name the regions or facilities for the live service, the backups, and any subprocessors. The Scoping Guide’s SIEM discussion says methods of assessment vary with the deployment, and that when an external provider hosts the SIEM or the log storage, that portion of the provider is in the assessment scope.

The same discussion treats longer-term, or cold, storage of logs as in scope as well, and says to record the method and the location. A retention bucket is not an afterthought.

What you still write down

RecordWhat the Level 2 materials point toStarter
Asset inventoryEach SPA, including whether it handles CUI or only security protection data.Inventory and data flow
System security planTreatment of the assets, and the external provider relationship. The guide says you need not embed every asset name in the plan.SSP section
Network diagramThe assessment scope, including these assets and the path to any external service.Your diagram. The data-flow table is a checklist beside it, not the diagram.
Responsibility matrixProvider service description and customer responsibility matrix for an external service provider.Matrix

Agreements

The Scoping Guide tells the organization to consider the agreements with the provider, including service levels, memoranda, and contracts, insofar as they support the security objectives. Keep the contract clause that covers incident notice, data location, and return of data with the matrix. The contract is not a substitute for the inventory or the plan.