Skip to content

Security Assessment (CA)

CA.L2-3.12.1 – Security Control Assessment

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

Assessment Objectives

Source: NIST SP 800-171A, p. 51.

Determine if:

  • [a] the frequency of security control assessments is defined; and
  • [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, p. 51.

Examine: [SELECT FROM: Security assessment and authorization policy; procedures addressing security assessment planning; procedures addressing security assessments; security assessment plan; system security plan; other relevant documents or records].

Interview: [SELECT FROM: Personnel with security assessment responsibilities; personnel with information security responsibilities].

Test: [SELECT FROM: Mechanisms supporting security assessment, security assessment plan development, and security assessment reporting].

Discussion

Source: NIST SP 800-171 Rev. 2, pp. 34-35.

Organizations assess security controls in organizational systems and the environments in which those systems operate as part of the system development life cycle. Security controls are the safeguards or countermeasures organizations implement to satisfy security requirements. By assessing the implemented security controls, organizations determine if the security safeguards or countermeasures are in place and operating as intended. Security control assessments ensure that information security is built into organizational systems; identify weaknesses and deficiencies early in the development process; provide essential information needed to make risk-based decisions; and ensure compliance to vulnerability mitigation procedures. Assessments are conducted on the implemented security controls as documented in system security plans. Security assessment reports document assessment results in sufficient detail as deemed necessary by organizations, to determine the accuracy and completeness of the reports and whether the security controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security requirements. Security assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted. Organizations ensure that security assessment results are current, relevant to the determination of security control effectiveness, and obtained with the appropriate level of assessor independence. Organizations can choose to use other types of assessment activities such as vulnerability scanning and system monitoring to maintain the security posture of systems during the system life cycle. NIST SP 800-53 provides guidance on security and privacy controls for systems and organizations. SP 800-53A provides guidance on developing security assessment plans and conducting assessments.

Further Discussion

Avoid a “set it and forget it” mentality when implementing security controls. The security landscape is constantly changing. Reassess existing controls at periodic intervals in order to validate their effectiveness in your environment. Set the assessment schedule according to organizational needs. Consider regulatory obligations and internal policies when assessing the controls. Outputs from security control assessments typically include:

  • documented assessment results;
  • proposed new controls, or updates to existing controls;
  • remediation plans; and
  • newly identified risks.

This requirement, CA.L2-3.12.1, which ensures determining security controls are implemented properly, promotes effective security assessments for organizational systems mandated by CA.L2-3.12.3.

Examples

  • You are in charge of IT operations. You need to ensure that the security controls implemented within the system are achieving their objectives [b]. Taking the requirements outlined in your SSP as a guide, you conduct annual written reviews of the security controls to ensure they meet your organization’s needs. When you find controls that do not meet requirements, you propose updated or new controls, develop a written implementation plan, document new risks, and execute the changes.

Potential Assessment Considerations

  • Are security controls assessed at least annually [a]?
  • Is the output of the security controls assessment documented [b]?

Key References

  • NIST SP 800-171 Rev. 2 3.12.1

CA.L2-3.12.2 – operational Plan of Action

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

Assessment Objectives

Source: NIST SP 800-171A, p. 51.

Determine if:

  • [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified;
  • [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities; and
  • [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, p. 51.

Examine: [SELECT FROM: Security assessment and authorization policy; procedures addressing plan of action; system security plan; security assessment plan; security assessment report; security assessment evidence; plan of action; other relevant documents or records].

Interview: [SELECT FROM: Personnel with plan of action development and implementation responsibilities; personnel with information security responsibilities].

Test: [SELECT FROM: Mechanisms for developing, implementing, and maintaining plan of action].

Discussion

Source: NIST SP 800-171 Rev. 2, p. 35.

The plan of action is a key document in the information security program. Organizations develop plans of action that describe how any unimplemented security requirements will be met and how any planned mitigations will be implemented. Organizations can document the system security plan and plan of action as separate or combined documents and in any chosen format. Federal agencies may consider the submitted system security plans and plans of action as critical inputs to an overall risk management decision to process, store, or transmit CUI on a system hosted by a nonfederal organization and whether it is advisable to pursue an agreement or contract with the nonfederal organization.

Further Discussion

When you write a plan of action, define the clear goal or objective of the plan. You may include the following in the action plan:

  • ownership of who is accountable for ensuring the plan’s performance;
  • specific steps or milestones that are clear and actionable;
  • assigned responsibility for each step or milestone;
  • milestones to measure plan progress; and
  • completion dates.

This requirement, CA.L2-3.12.2, which ensures developing and implementing operational plans of action to correct and reduce vulnerabilities in systems, is driven by risk management requirement RA.L2-3.11.1, which promotes periodically assessing risk to organizational systems. CA.L2-3.12.2 promotes monitoring security controls on an ongoing basis as defined in requirement CA.L2-3.12.3. An operational plan of action in accordance with CA.L2-3.12.2 differs from a CMMC assessment POA&M as described in 32 CFR § 170.21. The assessment POA&M places conditions on which security requirements can be assessed as NOT MET and allows the OSA to qualify for a CMMC Status of Conditional Level 2 (Self), Conditional Level 2 (C3PAO), or Conditional Level 3 (DIBCAC). Operational plans of action are not subject to the 180 day POA&M closeout requirement. Severity, availability of remediation, and business requirements are among the factors to consider when creating and maintaining operational plans of action.

Examples

  • As IT director, one of your duties is to develop action plans when you discover that your company is not meeting security requirements or when a security issue arises [b]. A recent vulnerability scan identified several items that need to be addressed so you develop a plan to fix them [b]. Your plan identifies the people responsible for fixing the issues, how to do it, and when the remediation will be completed [b]. You also define how to verify that the person responsible has fixed the vulnerability [b]. You document this in an operational plan of action that is updated as milestones are reached [b]. You have a separate resource review the modifications after they have been completed to ensure the plan has been implemented correctly [c].

Potential Assessment Considerations

  • Is there an action plan to remediate identified weaknesses or deficiencies [a]?
  • Is the action plan maintained as remediation is performed [b]?
  • Does the action plan designate remediation dates and milestones for each item [c]?

Key References

  • NIST SP 800-171 Rev. 2 3.12.2

CA.L2-3.12.3 – Security Control Monitoring

Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.

Assessment Objectives

Source: NIST SP 800-171A, p. 52.

Determine if:

  • [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, p. 52.

Examine: [SELECT FROM: Security planning policy; organizational procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; other relevant documents or records].

Interview: [SELECT FROM: Personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities].

Test: [SELECT FROM: Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan].

Discussion

Source: NIST SP 800-171 Rev. 2, p. 35.

Continuous monitoring programs facilitate ongoing awareness of threats, vulnerabilities, and information security to support organizational risk management decisions. The terms continuous and ongoing imply that organizations assess and analyze security controls and information security-related risks at a frequency sufficient to support risk-based decisions. The results of continuous monitoring programs generate appropriate risk response actions by organizations. Providing access to security information on a continuing basis through reports or dashboards gives organizational officials the capability to make effective and timely risk management decisions. Automation supports more frequent updates to hardware, software, firmware inventories, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Monitoring requirements, including the need for specific monitoring, may also be referenced in other requirements. NIST SP 800-137 provides guidance on continuous monitoring.

Further Discussion

Provide a plan for monitoring the state of security controls on a recurring basis that occurs more frequently than the periodic assessments discussed in CA.L2-3.12.1. This process provides a mechanism to assess the overall security posture of your organization, which directly relates to activities discussed in CA.L2-3.12.4. As a result, the process not only maintains awareness of vulnerabilities and threats, but it also informs management of the effectiveness of the security controls in determining if security controls are current and for management to make an acceptable risk decision.

Examples

  • You are responsible for ensuring your company fulfills all cybersecurity requirements for its DoD contracts. You review those requirements and the security controls your company has put in place to meet them. You then create a plan to evaluate each control regularly over the next year. You mark several controls to be evaluated by a third-party security assessor. You assign other IT resources in the organization to evaluate controls within their area of responsibility. To ensure progress you establish recurring meetings with the accountable IT staff to assess continuous monitoring progress, review security information, evaluate risks from gaps in continuous monitoring, and produce reports for your management [a].

Potential Assessment Considerations

  • Are the security controls that need to be continuously monitored identified [a]?
  • Is the timeframe for continuous monitoring activities to support risk-based decision making defined [a]?
  • Is the output of continuous monitoring activities provided to stakeholders [a]?

Key References

  • NIST SP 800-171 Rev. 2 3.12.3

CA.L2-3.12.4 – System Security Plan

Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

Assessment Objectives

Source: NIST SP 800-171A, p. 52.

Determine if:

  • [a] a system security plan is developed;
  • [b] the system boundary is described and documented in the system security plan;
  • [c] the system environment of operation is described and documented in the system security plan;
  • [d] the security requirements identified and approved by the designated authority as non-applicable are identified;
  • [e] the method of security requirement implementation is described and documented in the system security plan;
  • [f] the relationship with or connection to other systems is described and documented in the system security plan;
  • [g] the frequency to update the system security plan is defined; and
  • [h] system security plan is updated with the defined frequency.

Potential Assessment Methods and Objects

Source: NIST SP 800-171A, p. 52.

Examine: [SELECT FROM: Security planning policy; procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; other relevant documents or records].

Interview: [SELECT FROM: Personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities].

Test: [SELECT FROM: Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan].

Discussion

Source: NIST SP 800-171 Rev. 2, pp. 35-36.

System security plans relate security requirements to a set of security controls. System security plans also describe, at a high level, how the security controls meet those security requirements, but do not provide detailed, technical descriptions of the design or implementation of the controls. System security plans contain sufficient information to enable a design and implementation that is unambiguously compliant with the intent of the plans and subsequent determinations of risk if the plan is implemented as intended. Security plans need not be single documents; the plans can be a collection of various documents including documents that already exist. Effective security plans make extensive use of references to policies, procedures, and additional documents (e.g., design and implementation specifications) where more detailed information can be obtained. This reduces the documentation requirements associated with security programs and maintains security-related information in other established management/operational areas related to enterprise architecture, system development life cycle, systems engineering, and acquisition. Federal agencies may consider the submitted system security plans and plans of action as critical inputs to an overall risk management decision to process, store, or transmit CUI on a system hosted by a nonfederal organization and whether it is advisable to pursue an agreement or contract with the nonfederal organization. NIST SP 800-18 provides guidance on developing security plans.

Further Discussion

A system security plan (SSP) is a document that outlines how an organization implements its security requirements. OSAs must have an SSP in place at the time of assessment to describe each information system within the CMMC Assessment Scope. The absence of an up-to-date SSP at the time of the assessment would result in a finding that an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012. OSAs are free to choose the format of their SSP. At a minimum, an SSP must include:

  • Description of the CMMC Assessment Scope;
  • CMMC Assessment Scope Description: high-level description of the assets within the assessment scope 186;
  • Description of the Environment of Operation: physical surroundings in which an information system processes, stores, and transmits information;
  • Identified and Approved Security Requirements: requirements levied on an information system that are derived from applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, procedures, or organizational mission/business case needs to ensure the confidentiality, integrity, and availability of the information being processed, stored, or transmitted;

186 There is no requirement to embed every asset in the SSP. .

  • Implementation Method for Security Requirements: description of how the identified and approved security requirements are implemented with the system or environment;
  • Connections and Relationships to Other Systems and Networks: description of related, dependent, and interconnected systems; and
  • Defined Frequency of Updates: at least annually.

In addition to the requirements above, an SSP often includes:

  • general information system description: technical and functional description;
  • design philosophies: defense-in-depth strategies and allowed interfaces and network protocols; and
  • roles and responsibilities: description of the roles and responsibilities for key personnel, which may include the system owner, system custodian, authorizing officials, and other stakeholders This requirement, CA.L2-3.12.4, which requires developing, documenting, and updating system security plans, promotes effective information security within organizational systems required by SC.L2-3.13.2, as well as other system and communications protection requirements.

Examples

  • You are in charge of system security. You develop an SSP and have senior leadership formally approve the document [a]. The SSP explains how your organization handles CUI and defines how that data is stored, transmitted, and protected [d,e]. The criteria outlined in the SSP is used to guide configuration of the network and other information resources to meet your company’s goals. Knowing that it is important to keep the SSP current, you establish a policy that requires a formal review and update of the SSP each year [g,h].

Potential Assessment Considerations

  • Do mechanisms exist to develop and periodically update an SSP [a,g]?
  • Are security requirements identified and approved by the designated authority as non-applicable documented [d]?

Key References

  • NIST SP 800-171 Rev. 2 3.12.4