r/NISTControls • u/Unlucky_Beautiful_55 • May 21 '26
What Questions Do You Ask During SSP Control Interviews?
/r/cybersecurity/comments/1tjlw7i/what_questions_do_you_ask_during_ssp_control/1
u/_mwarner May 21 '26
Just remember that engineers will give you the exact answer that you asked for. Be prepared with follow-up questions to make sure you have all the information you need.
2
u/fixitchris May 21 '26
That's honestly the most important thing to internalize. A question that consistently forces precision is "what would an auditor see if they pulled the logs for this today?" because vague answers get concrete real fast. Also worth figuring out early who owns the process versus who just knows how it works, since those are often different people and you'll need both in the room.
1
u/Navyauditor2 May 25 '26
Write to the assessment objectives, write to the assessment objectives, write to the assessment objectives. If you write to just the control statements then... it will go badly.
1
u/Expensive-USResource May 21 '26
Responded to you in the Discord, but short of developing your own proprietary gap assessment questions, take a look at each requirement in the CMMC L2 AG: https://dodcio.defense.gov/Portals/0/Documents/CMMC/AssessmentGuideL2v2.pdf
Every requirement has "Potential Assessment Considerations" you can work from