NIST SP 800-171 Rev 3
03.12 CA (Security Assessment and Monitoring)

NIST SP 800-171 Rev 3 03.12.01: Security Assessment

Assess security requirements in the system at defined frequency to determine if controls are implemented correctly, operating as intended, and producing the desired outcome.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 47 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APRA CPS 234 · 3 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P30 Independence and Skill of Testing Personnel
  • SEC01-BP03 Identify and validate control objectives
  • SEC11-BP03 Perform regular penetration testing
  • SEC11-BP07 Regularly assess security properties of the pipelines
  • 53A-3.2.2 Select Procedures to Assess the Controls
  • 53A-3.3 Conduct Control Assessments
  • 53A-E Assessment Reports
  • ASBv3-PV-7 Conduct regular red team operations
  • PV-2 Audit and enforce secure configurations

C5 (Germany) · 2 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests
  • CFTC-SS-15 Controls Testing
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems

CIS Controls v8 · 2 controls

  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.4 Validate Security Measures

FedRAMP High · 2 controls

  • CA-2 Control Assessments
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))

FedRAMP Moderate · 2 controls

  • CA-2 Control Assessments
  • CM-4(2) Impact Analyses | Verification of Controls (CM-4(2))

ISO 27001:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 2 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27701:2019 · 2 controls

  • 5.7.2 Internal audit
  • 6.15.2 Information security reviews

NIS2 Directive · 2 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

PCI DSS 4.0 · 2 controls

  • 11.4.3 11.4.3 External penetration testing annually and after change
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions

SOC 2 · 1 control

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.12 CA (Security Assessment and Monitoring)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.12.01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 47 it maps to, and the evidence behind each claim, over MCP and REST.