03.12.01: Security Assessment
Control Familly: Security Assessment and Monitoring
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-53 [8]
SP 800-53A [57]
SP 800-37 [59]
SP 800-115 [58]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.12.01
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
CA-02
Assess the security requirements for the system and its environment of operation [Assignment: organization-defined frequency] to determine if the requirements have been satisfied.
Discussion:
By assessing the security requirements, organizations determine whether the necessary safeguards and countermeasures are implemented correctly, operating as intended, and producing the desired outcome. Security assessments identify weaknesses in the system and provide the essential information needed to make risk-based decisions. Security assessment reports document assessment results in sufficient detail as deemed necessary by the organization to determine the accuracy and completeness of the reports. Security assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted.
Assessment Methods and Objectives
Examine [SELECT FROM: security assessment and monitoring policy and procedures; procedures for security assessment planning; security assessment plan; security assessment report; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with security assessment responsibilities; personnel with information security responsibilities]
Test [SELECT FROM: mechanisms for supporting security assessments, processes for security assessment plan development, or security assessment reporting]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.12.01.ODP[01]: the frequency at which to assess the security requirements for the system and its environment of operation is defined.
A.03.12.01: the security requirements for the system and its environment of operation are assessed <A.03.12.01.ODP[01]: frequency> to determine if the requirements have been satisfied.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A