CCI-000252
CCI-000252 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
DoD has defined the frequency as annually for technical controls, annually for a portion of management and operation controls such that all are reviewed in a 3 year period except for those requiring more frequent review as defined in other site or overarching policy. NOTE: Technical, Management and Operational is IAW NIST SP 800-53 Table 1-1. *Comment* The items required within this control are being split into the security plan and security assessment report to eliminate creation of an additional artifact.
Validation Procedures
The organization being inspected/assessed is automatically compliant with this CCI because they are covered at the DoD level. DoD has defined the frequency as annually for technical controls, annually for a portion of management and operation controls such that all are reviewed in a 3 year period except for those requiring more frequent review as defined in other site or overarching policy. NOTE: Technical, Management and Operational is IAW NIST SP 800-53 Table 1-1.
Compelling Evidence
Automatically Compliant