Scoring Methodology and the Need for a GRC

The NIST SP 800-171 DoD Assessment Methodology details the exact score allowed for each 110 security requirements. There’s a substantial discussion for methodology in accepting and evaluating acceptable artifacts and compensating controls as evidence of having met requirements and how to score items that are determined to be not applicable. The document serves as the proper scoring either via self-reporting or as validated by the DoD assessor. Everyone involved in NIST 171 needs to read and fully implement this guidance.

Scoring Requirements

Figure 9 NIST 171 Assessment Methodology Requirements scoring guidance (Open this image full screen.)

Compliance program management should have their scoring established before completing their SPRS. The process of reporting the Self-Assessment is simply the time spent selecting the correct response, rather than the act of evaluating and determining the right answer.

SPRS Scoring Values

Figure 10 NIST 171 Scoring values (Open this image full screen.)

Main Menu