NIST 800-171 · Security Assessment

Requirement 3.12.4

SPRS weight
SPRS weight: N/A
POA&M eligibility
Not POA&M-eligible
Assessment objectives
8 assessment objectives

Official requirement text

Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.12.4[a]a system security plan is developed.
  2. 3.12.4[b]the system boundary is described and documented in the system security plan.
  3. 3.12.4[c]the system environment of operation is described and documented in the system security plan.
  4. 3.12.4[d]the security requirements identified and approved by the designated authority as non-applicable are identified.
  5. 3.12.4[e]the method of security requirement implementation is described and documented in the system security plan.
  6. 3.12.4[f]the relationship with or connection to other systems is described and documented in the system security plan.
  7. 3.12.4[g]the frequency to update the system security plan is defined.
  8. 3.12.4[h]system security plan is updated with the defined frequency.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.