NIST 800-171 · Security Assessment

Requirement 3.12.2

SPRS weight
SPRS weight: 3
POA&M eligibility
Not POA&M-eligible
Assessment objectives
3 assessment objectives

Official requirement text

Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.12.2[a]deficiencies and vulnerabilities to be addressed by the plan of action are identified.
  2. 3.12.2[b]a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities.
  3. 3.12.2[c]the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.