NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)
171A 03.12 Security Assessment and Monitoring

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) 171A-03.12.01: Security Assessment

Determines whether the requirements are assessed at the defined frequency to establish whether they are implemented correctly and producing the intended outcome, and whether results are documented.

Maintained by Gerard BlokdykVerified against the published standard

What else in your programme already covers this

This control maps to 34 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation

FedRAMP High · 3 controls

FedRAMP Moderate · 3 controls

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.34 Protection of information systems during audit testing 

ISO 27002:2022 · 3 controls

  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.34 Protection of information systems during audit testing
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • PV-2 Audit and enforce secure configurations

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

SOC 2 · 1 control

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 171A 03.12 Security Assessment and Monitoring

Query this from an agent

The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.