CCI-000245
CCI-000245 Definition
The organization develops a security assessment plan for the information system and its environment of operation.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed will document these security assessment plan requirements as part of the DoD approved Security Plan. Security plan templates are provided through eMASS and the Knowledge Service. *Comment* The items required within this control are being split into the security plan and security assessment report to eliminate creation of an additional artifact.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the Security Plan to validate *security assessment blocks* are complete.
Compelling Evidence
1.) Signed and dated Security Assessment Plan