03.12: Security Assessment and Monitoring

Controls

03.12.01: Security Assessment

Assess the security requirements for the system and its environment of operation [Assignment: organization-defined frequency] to determine if the requirements have been satisfied.

03.12.02: Plan of Action and Milestones

Develop a plan of action and milestones for the system: To document the planned remediation actions to correct weaknesses or deficiencies noted during security assessments and To reduce or eliminate known system vulnerabilities. Update the existing plan of action and milestones based on the findings from: Security assessments, Audits or reviews, and Continuous monitoring activities.

03.12.03: Continuous Monitoring

Develop and implement a system-level continuous monitoring strategy that includes ongoing monitoring and security assessments.

03.12.05: Information Exchange

Approve and manage the exchange of CUI between the system and other systems using [Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements]. Document interface characteristics, security requirements, and responsibilities for each system as part of the exchange…