NIST 800-171 · Risk Assessment
Requirement 3.11.1
- SPRS weight
- SPRS weight: 3
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 2 assessment objectives
Official requirement text
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.11.1[a]the frequency to assess risk to organizational operations, organizational assets, and individuals is defined.
- 3.11.1[b]risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.