NIST 800-171 · Security Assessment
Requirement 3.12.4
- SPRS weight
- SPRS weight: N/A
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 8 assessment objectives
Official requirement text
Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.12.4[a]a system security plan is developed.
- 3.12.4[b]the system boundary is described and documented in the system security plan.
- 3.12.4[c]the system environment of operation is described and documented in the system security plan.
- 3.12.4[d]the security requirements identified and approved by the designated authority as non-applicable are identified.
- 3.12.4[e]the method of security requirement implementation is described and documented in the system security plan.
- 3.12.4[f]the relationship with or connection to other systems is described and documented in the system security plan.
- 3.12.4[g]the frequency to update the system security plan is defined.
- 3.12.4[h]system security plan is updated with the defined frequency.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.