1Overview
RA.L2-3.11.1 opens the Risk Assessment family with the requirement to assess risk periodically. It requires that the organization periodically assess the risk to its operations, assets, and individuals arising from operating systems that process, store, or transmit CUI, so that security decisions rest on an understanding of the risks that actually face the organization. It is a three-point requirement that cannot be deferred on a plan of action.
Security controls are worth applying because they address risk, and understanding that risk is what makes the security program deliberate rather than arbitrary. This control requires the organization to define how often it will assess risk and then actually assess, at that frequency, the risk that operating CUI systems poses to its mission, assets, and people. The result is a current picture of the threats and vulnerabilities the organization faces, which informs where to focus protection. Its three-point weight reflects that a program without a risk assessment is guessing at its own priorities.
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
The requirement has two elements the assessment objectives make explicit: a defined frequency, and assessment at that frequency. The organization decides how often it will assess risk, then assesses the risk to operations, assets, and individuals from operating systems that process, store, or transmit CUI. Periodic assessment keeps the risk picture current as the environment and threats change, so the program is guided by present risk rather than a one-time snapshot.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.11.1 into two objectives: define the frequency and assess at that frequency.
The frequency to assess risk to organizational operations, assets, and individuals is defined. How often risk is assessed is set.
Risk resulting from the operation of a system that processes, stores, or transmits CUI is assessed with the defined frequency. Risk is actually assessed on schedule.
The two objectives are the frequency and the assessment. The common gap is at objective [b], where a frequency is defined but the assessment does not actually happen on that schedule. The assessor looks for a defined frequency and evidence of assessment at that cadence.
3Failure Patterns
The failures are about risk assessment that is undefined or does not recur.
No defined frequency
Without setting how often risk is assessed, the assessment has no schedule and tends not to recur. Defining the frequency establishes the cadence.
One-time assessment
A risk assessment done once and never repeated goes stale as the environment and threats change. Periodic assessment at the defined frequency keeps the picture current.
Assessment not tied to CUI systems
A generic risk exercise that does not address the risk from operating CUI systems misses the control's focus. The assessment has to cover the risk those systems pose.
4Ownership
This is a security and management-owned control.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Defines the frequency and conducts the risk assessment covering CUI systems. Owns the risk assessment records. |
| Management | Uses the risk assessment to guide security priorities. |
| Program lead | Confirms the assessment recurs at the defined frequency and retains the records. |
5Tooling
The control is largely procedural, delivered by a defined and recurring risk assessment.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined assessment frequency | A set cadence for assessing risk. |
| [b] | Risk assessment covering CUI systems | Assessment of the risk from operating CUI systems at that cadence. |
The caveat is that the assessment has to actually recur at the defined frequency and cover the CUI systems. A frequency on paper without assessments on that schedule, or a generic exercise that ignores CUI systems, leaves the control unmet. The assessor examines the frequency and the recurring assessment, so both objectives have to hold.
6Evidence
The satisfied version of 3.11.1 shows a defined frequency and recurring risk assessments.
| Evidence | What it demonstrates |
|---|---|
| Defined assessment frequency | Objective [a]. How often risk is assessed. |
| Risk assessment records | Objective [b]. Risk assessed at the defined frequency, covering CUI systems. |
The evidence should show a defined assessment frequency and risk assessments performed at that cadence covering CUI systems. The defined frequency together with the assessment records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
A program guided by stale risk drifts from reality
Risk changes as systems and threats change, so this three-point control asks for a defined frequency and recurring assessment of the risk from operating CUI systems. Establishing a real, periodic risk assessment is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.11.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.11.1[a] and 3.11.1[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing RA.L2-3.11.1 among the three-point basic security requirements. ecfr.gov