Execute the Assess step per NIST SP 800-37 Rev 2 Chapter 3 Step 5. Determine whether controls selected for implementation are implemented correctly + operating as intended + producing the desired outcome with respect to meeting the security and privacy requirements. Tasks include (A-1) select assessor (independent + appropriately qualified + with documented assessment plan reviewed and approved), (A-2) develop security and privacy assessment plans (SAP) aligned with SP 800-53A assessment procedures, (A-3) review and approve assessment plans, (A-4) assess controls per the SAP using examine + interview + test methods, (A-5) develop security and privacy assessment reports (SAR), (A-6) initial remediation actions on findings, (A-7) develop Plan of Action and Milestones (POAM) for unremediated findings. Assessment outputs feed the Authorize decision.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.