CCI-000246
CCI-000246 Definition
The organization's security assessment plan describes the security controls and control enhancements under assessment.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed will ensure the Security Plan identifies the security controls and control enhancements under assessment. *Comment* The items required within this control are being split into the security plan and security assessment report to eliminate creation of an additional artifact.
Validation Procedures
The organization conducting the inspection/assessment obtains the security assessment plan to verify the plan identifies the security controls and those control enhancements under assessment.
Compelling Evidence
1.) Signed and dated Security Assessment Plan, referencing section which identifies the security controls and control enhancements under assessment