Skip to content

Security Assessment

Security Assessment is the self-governance family. Don’t wait for the assessor to find problems — test your own controls, track your gaps, monitor continuously, and keep the SSP current.

Test (3.12.1) — Periodically assess whether your controls work in practice. Annual self-assessment at minimum, with quarterly spot-checks.

Track (3.12.2) — Every gap goes in the POA&M with an owner, target date, and remediation plan. Living document reviewed monthly.

Monitor (3.12.3) — Continuous monitoring between assessments. Compliance dashboards, alerts for control degradation, regular posture reviews.

Document (3.12.4) — The SSP: your complete, current description of the CUI boundary, environment, control implementations, and connections. Updated within 30 days of any change.


RefShort NameWhat It Covers
3.12.1Test Your ControlsPeriodic self-assessment of control effectiveness
3.12.2Track Every GapPOA&M with owners, milestones, and target dates
3.12.3Monitor ContinuouslyOngoing monitoring between periodic assessments
3.12.4Maintain the SSPSystem Security Plan — complete, current, specific