CCI-000573
CCI-000573 Definition
Review the plans in accordance with organization-defined frequency.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The information system owner as part of the annual security control review will also review the security plan annually. Documentation of security plan reviews is required as an audit trail. DoD has defined the frequency as annually.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the audit records of security plan reviews to verify the security plan has been reviewed annually. DoD has defined the frequency as annually.
Compelling Evidence
1.) System security plan (SSP) update records.