🛡️ CMMC 2.0 Access Control Matrix

ACME Technology Services Corporation - Training Environment

CMMC Level 2

Target Compliance

NIST 800-171

110 Controls

64 Employees

16 Role Types

4 Network Zones

Segmented Access

🔒 CUI Assets (In-Scope)

  • Primary Data Server CUI-001
  • Azure Cloud Backup CUI-002
  • Contract Coordinator Workstations CUI-003-005
  • CISO Management Workstation CUI-006
  • Secure File Server CUI-007

🔧 Security Protection Assets

  • Enterprise Firewall SPA-001
  • VPN Gateway SPA-002
  • Endpoint Protection SPA-004
  • SIEM Tools SPA-005
  • Badge Access Control SPA-006

⚠️ Contractor Risk Managed

  • IT Support Workstations CRMA-001-003
  • Secure Printers CRMA-004
  • Warehouse Inventory System CRMA-005

🚫 Out-of-Scope Assets

  • Personal Laptops OOS-001
  • HR Systems OOS-002
  • Marketing Systems OOS-003
  • Guest Wi-Fi OOS-004
  • Facility Management OOS-005

🌐 Network Zone Segmentation

CUI Zone

Secure access to CUI assets

Management Zone

Admin & IT operations

Guest Network

Isolated from internal systems

OT Network

Building control systems

🎛️ Instructor Controls

📊 Access Control Matrix

Read (R) - View only access
Write (W) - Modify content
Execute (E) - Run operations
Admin (A) - Full control
Deny (-) - No access

📋 Audit Log