Latest / Story
What Is a Security Assessment Plan?
You need to prove your controls work, and you need a plan that holds up under review.
You are chasing an ATO (Authorization to Operate).
A security assessment plan is the document that says how your controls will be tested.
NIST describes it in the Risk Management Framework (RMF), a seven step process for managing security risk 800-37.
Who writes the plan?
The control assessor writes the plan, working with the system owner and security staff 800-37.
The Authorizing Official (AO) approves it.
The AO is the senior leader who accepts the system's risk 800-37.
What goes in it?
Scope: which controls are in, and whether the assessment is full or partial 800-53A.
Assessment procedures: one procedure per control, taken from NIST SP 800-53A and tailored to your system 800-53A.
Roles and responsibilities: who examines, who interviews, and who tests 800-37.
Schedule and resources: when testing happens and what the assessor needs to see 800-37.
Approval: the AO's sign-off before any testing starts 800-37.
How does it relate to the SSP?
Your SSP (System Security Plan) describes the controls you built 800-53A.
The assessment plan describes how those controls will be checked.
The assessment report records what the testing found 800-53A.
The assessor builds the plan from your SSP, not from scratch 800-53A.
How is each control tested?
Each control gets tested with one or more of three methods 800-53A.
Examine: read and inspect documents, settings, and records 800-53A.
Interview: talk to the people who run and manage the controls 800-53A.
Test: run the control and compare what happens to what should happen 800-53A.
Two settings tune each method: depth, which is rigor, and coverage, which is scope 800-53A.
Each setting uses basic, focused, or comprehensive 800-53A.
A worked example: AC-2
Here is a small example using AC-2, Account Management, from NIST SP 800-53 800-53.
Objective: determine if account types are defined, accounts follow policy, access is authorized, and accounts are reviewed 800-53A.
Examine: read the access control policy, the account lists, the audit records, and the SSP 800-53A.
Interview: ask the system and network administrators how accounts are managed 800-53A.
Test: exercise the account management process and its automated tools 800-53A.
What should you do first?
Start with your SSP and list every control it describes 800-53A.
That list becomes the scope of your assessment plan.
Pick one control, write its procedure, and run it before writing the rest.
Evidence collection takes time when done by hand.
PolicyCortex reads live Azure configuration with 33 collectors, and its output is evaluated against NIST 800-53 and 800-171.
Re-verification after remediation confirms the fix actually worked.
See how it works: policycortex.com.
Sources
- NIST SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations (December 2018)
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (September 2020)
- NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls in Information Systems and Organizations (January 2022)