03.12.01: Security Assessment

Control Familly: Security Assessment and Monitoring

SPRS: N/A

Top Ten Failed Requirement: N/A

Supporting Publications:

  • SP 800-53 [8]

  • SP 800-53A [57]

  • SP 800-37 [59]

  • SP 800-115 [58]

Referenced in: N/A

Control Type: N/A

CPCSC Level 2: 03.12.01

CMMC Level(s): N/A

Derived From: NIST SP 800-53r5

  • CA-02

Assess the security requirements for the system and its environment of operation [Assignment: organization-defined frequency] to determine if the requirements have been satisfied.

Discussion:

By assessing the security requirements, organizations determine whether the necessary safeguards and countermeasures are implemented correctly, operating as intended, and producing the desired outcome. Security assessments identify weaknesses in the system and provide the essential information needed to make risk-based decisions. Security assessment reports document assessment results in sufficient detail as deemed necessary by the organization to determine the accuracy and completeness of the reports. Security assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted.

Assessment Methods and Objectives

Examine [SELECT FROM: security assessment and monitoring policy and procedures; procedures for security assessment planning; security assessment plan; security assessment report; system security plan; other relevant documents or records]

Interview [SELECT FROM: personnel with security assessment responsibilities; personnel with information security responsibilities]

Test [SELECT FROM: mechanisms for supporting security assessments, processes for security assessment plan development, or security assessment reporting]

NIST SP 800-171A r3 Determining Statements Determine if:

A.03.12.01.ODP[01]: the frequency at which to assess the security requirements for the system and its environment of operation is defined.

A.03.12.01: the security requirements for the system and its environment of operation are assessed <A.03.12.01.ODP[01]: frequency> to determine if the requirements have been satisfied.