03.12.01: Security Assessment
Control Family:
Previous Version:
- NIST Special Publication 800-171 Revision 2:
- 3.12.1: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application
Requirements
- Assess the security requirements for the system and its environment of operation [Assignment: organization-defined frequency] to determine if the requirements have been satisfied.
Discussion
By assessing the security requirements, organizations determine whether the necessary safeguards and countermeasures are implemented correctly, operating as intended, and producing the desired outcome. Security assessments identify weaknesses in the system and provide the essential information needed to make risk-based decisions. Security assessment reports document assessment results in sufficient detail as deemed necessary by the organization to determine the accuracy and completeness of the reports. Security assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted.