CCI-001040
CCI-001040 Definition
The organization defines the frequency with which to review and update the current risk assessment policy.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
DoD has defined the frequency as reviewed annually - updated as appropriate but at least within 10 years of date of issuance.
Validation Procedures
The organization being inspected/assessed is automatically compliant with this CCI because they are covered at the DoD level. DoD has defined the frequency as reviewed annually - updated as appropriate but at least within 10 years of date of issuance.
Compelling Evidence
Automatically compliant per DoDI 8510.01 which adopts NIST SP 800-30 as the DoD risk assessment policy.