Part III: The DoD NIST 171 Assessment as a GRC Schema

CMMC 2.0 Interim Final Rule maintains the established NIST 171 assessment cycle allowing most contractors associated with Foundational / Level 1 and a subset of Advanced / Level 2 programs to perform annual self-assessments. This means those contractors will continue to use the SPRS to upload their internally managed audit of the NIST 171 110 security requirements, NIST SP 800-171 (disa.mil). A portion of the Advanced / Level 2 programs will require triennial third-party assessments. Expert / Level 3 programs will require triennial assessments conducted by government officials.

All DoD NIST 171 Assessment begins with compliance program management organizing their strategy and work plan. This involves connecting all parts of the NIST 171, 171A, and 172, including each requirement’s assessment and implementation guidance, understanding the overall schema of records, and assigning the connected elements into some sort of GRC. Connecting these record elements facilitates the management of the NIST 171 assessment cycle. The GRC system needs to track each family, and requirements within that family, along with each requirement’s implementation guidance, assessment elements, scoring value, and associated tags for naming or calling it as part of either a NIST 171 low, medium, or high data set, or as part of a CMMC Level 1, Level 2 or Level 3 array for that level of Assessment. This is foundationally important because documenting and planning the assessment should be the easy part.

Regardless of whether the entity intends to complete a Self-Assessment, a Third-Party Assessment, or will be required to undergo a Government Assessment, program owners will need to organize a System Security Plan (SSP) and Plan of Action & Milestone (POA&M) that tracks their progress against their catalog of controls and requirements. The accompanying documentation for all levels of Assessment must include a moderately mature ISMS as shown in Table 7 and as suggested by the NIST.HB.162 Appendix of Useful Plans, Policies, and Procedures to have ready for submission during any audit. [xxxiv]

Beyond the scope of the assessment, it will be necessary to achieve and maintain a capacity to associate NIST 171 and CMMC practice/requirements tags to assets, programs, and policy, so the assessment lifecycle maintains visibility and consistency. Even though the NIST 171 is designed to keep the overall burden of testing within reasonable levels, tracking progress against certain types of controls, such as Encryption, MFA, Incident Response, or Vulnerability Management, involves a large amount of asset-specific evidence, procedures for response and follow-up, and continuous monitoring that aligns with a declared structure of risk management. To Assess the NIST 171, the entity must design a program that meets its requirements. That is the hard part.

Plans you should have in place:  Policies and Procedures you should have: 

Business Continuity Plans
Contingency Plans
Continuity of Operations Plans 
Critical Infrastructure Plans 
Crisis Communications Plan 
Disaster Recovery Plans 
Incident Response Plan 
Incident Response Testing Plan 
Occupant Emergency Plan
Physical/Environmental Protection Plan 
Plan of Action
Security Assessment Plan 
Security Plan
System Security Plan

Access Control
Audit and Accountability 
Configuration Management 
Configuration Planning
Incident Response
Identification and Authentication 
Information Flow Control 
Information Flow Enforcement 
Information System Maintenance 
Media Protection
Media Sanitization and Disposal 
Mobile Code Implementation 
Password
Personnel Security

Physical and Environmental Protection 
Portable Media
Risk Assessment
Security Assessment and Authorization 
Security Awareness and Training 
Security Planning
Separation of Duties
System and Information Integrity 
System and Services Acquisition 
System and Communication Protection 
System Use (Acceptable Use)

Table 7 - Necessary Plans, Policies, and Procedures as suggested in the NIST.HB.162 for NIST 171 DFARS Assessment readiness

Main Menu