1Overview
CA.L2-3.12.1 opens the Security Assessment family with the requirement to check that controls actually work. It requires that the organization periodically assess the security controls in its systems to determine whether they are effective in their application, so that the program is verified rather than assumed. It is a five-point requirement that cannot be deferred on a plan of action.
Implementing a control and knowing it works are two different things. Controls can be misconfigured, drift out of effectiveness, or fail to do what was intended, and a program that never checks its own controls does not know which of them are actually protecting anything. This control requires periodic assessment of the security controls to determine their effectiveness in application, on a defined frequency, so the organization has current evidence that its controls do what they are supposed to. Its five-point weight reflects that unverified controls may be protecting nothing.
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
The requirement pairs a defined frequency with the assessment itself. The two assessment objectives are that the frequency of control assessments is defined, and that controls are assessed at that frequency to determine effectiveness in their application. Assessing effectiveness in application means checking not just that a control exists but that it works as intended in the actual environment. Doing so periodically keeps the verification current as the environment changes.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.12.1 into two objectives: define the frequency and assess controls at that frequency for effectiveness.
The frequency of security control assessments is defined. How often controls are assessed is set.
Security controls are assessed with the defined frequency to determine if the controls are effective in their application. Controls are checked for effectiveness on schedule.
The two objectives are the frequency and the effectiveness assessment. The common gap is at objective [b], where controls are assumed effective because they were implemented, without any check that they still work. The assessor looks for a defined frequency and evidence of periodic effectiveness assessment.
3Failure Patterns
The failures are about controls assumed effective but never verified.
Controls assumed rather than checked
Treating a control as effective because it was implemented ignores misconfiguration and drift. Assessing effectiveness in application verifies the control actually works.
One-time or no assessment
Assessing controls once and never again lets effectiveness erode unseen. Periodic assessment at the defined frequency keeps the verification current.
No defined frequency
Without a defined frequency, control assessment has no cadence and tends to lapse. Defining the frequency anchors the periodic assessment.
4Ownership
This is a security and compliance-owned control.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Defines the frequency and assesses controls for effectiveness in application. Owns the assessment records. |
| IT and system administrator | Supports the assessment with the technical detail of how controls are applied. |
| Program lead | Confirms assessment recurs at the defined frequency and retains the records. |
5Tooling
The control is delivered by a defined, recurring control assessment.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined assessment frequency | A set cadence for control assessments. |
| [b] | Control effectiveness assessment | Verification that controls work in their application, at that cadence. |
The caveat is that the assessment has to check effectiveness in application, not mere existence, and recur on the defined frequency. A checklist that confirms controls are present without testing whether they work does not meet the objective. The assessor examines the frequency and the effectiveness assessment, so both objectives have to hold.
6Evidence
The satisfied version of 3.12.1 shows a defined frequency and recurring effectiveness assessments.
| Evidence | What it demonstrates |
|---|---|
| Defined assessment frequency | Objective [a]. How often controls are assessed. |
| Control assessment records | Objective [b]. Controls assessed for effectiveness at that cadence. |
The evidence should show a defined frequency and control assessments performed at that cadence to determine effectiveness in application. The defined frequency together with the assessment records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
An implemented control is not necessarily a working one
Controls can be misconfigured or drift, so this five-point control asks for periodic assessment of whether they are effective in application. Building a real, recurring control assessment is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.12.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.12.1[a] and 3.12.1[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing CA.L2-3.12.1 among the five-point basic security requirements. ecfr.gov