CCI-000254
CCI-000254 Definition
The organization provides the results of the security control assessment against the information system and its environment of operation to organization-defined individuals or roles.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed will provide the SAR to at a minimum, the ISSO and ISSM. DoD has defined the individuals or roles as at a minimum, the ISSO and ISSM. *Comment* The items required within this control are being split into the security plan and security assessment report to eliminate creation of an additional artifact.
Validation Procedures
The organization conducting the inspection/assessment interviews at a minimum, the ISSO and ISSM to ensure the SAR has been received. DoD has defined the individuals or roles as at a minimum, the ISSO and ISSM.
Compelling Evidence
1.) Signed and dated Security Assessment Report 2.) Documentation listing the recipients of the SAR, at a minimum the ISSO and ISSM