NIST 800-171 · Risk Assessment

Requirement 3.11.2

SPRS weight
SPRS weight: 5
POA&M eligibility
Not POA&M-eligible
Assessment objectives
5 assessment objectives

Official requirement text

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.11.2[a]the frequency to scan for vulnerabilities in an organizational system and its applications that process, store, or transmit CUI is defined.
  2. 3.11.2[b]vulnerability scans are performed in an organizational system that processes, stores, or transmits CUI with the defined frequency.
  3. 3.11.2[c]vulnerability scans are performed in an application that contains CUI with the defined frequency.
  4. 3.11.2[d]vulnerability scans are performed in an organizational system that processes, stores, or transmits CUI when new vulnerabilities are identified.
  5. 3.11.2[e]vulnerability scans are performed in an application that contains CUI when new vulnerabilities are identified.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.