CA.L2-3.12.1Security Control Assessment
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
[a]
the frequency of security control assessments is defined; and[b]
security controls are assessed with the defined frequency to determine if the controls are effective in their application.
A third of the practices every quarter, tested rather than attested
Implementation
AO coverage. Addresses both Security Control Assessment objectives: defining the assessment frequency and assessing controls at that frequency to determine effectiveness.
Defined frequency. The assessment policy states: every practice is assessed at least annually; practices supporting identity, logging, media, and remote access are assessed quarterly because they change most often; any practice is reassessed within 30 days of a material change to the system that implements it. The schedule is a calendar in the GRC tool, not a paragraph in a policy nobody opens.
Assessment method. Each practice has an assessment procedure written the way an assessor would ask for it: examine (which artifact), interview (which role), and test (what the tester actually does). Testing is what makes this more than a self-attestation — for example, the access control practices are tested by attempting enclave access from a non-compliant device and confirming the deny, not by exporting a policy screenshot.
Sampling. Where a practice applies to many objects, the procedure defines the sample: ten endpoints across three device types, five offboardings from the last quarter, three retired assets. Samples are drawn from the authoritative inventory by the assessor, not supplied by the control owner.
Independence. The assessor is the ISSO or a peer engineer who does not own the control. Provider-operated controls are assessed by us against provider output; we do not accept the provider's own assurance letter as the only evidence.
Results. Each assessment closes with an effectiveness rating (effective / effective with observations / not effective) and a dated evidence bundle. Anything below effective opens a plan-of-action item with an owner the same week.
Maintenance. Quarterly, the schedule is checked for practices that slipped, and the procedures themselves are reviewed annually against the current assessment guide.
Accepted gap. Two practices implemented entirely by the provider are assessed by reviewing their evidence rather than by direct test, because we lack console access. The contract gives us audit rights we have not yet exercised; scheduling that test is a tracked action.
What the evidence looks like
- Assessment policy stating the frequency tiers and the change trigger
- Assessment calendar showing completed and upcoming practices
- Two completed assessment procedures with examine/interview/test results and sample lists
- Evidence bundle for one quarterly-tier practice with dates and assessor role
- Plan-of-action items generated from the last cycle
Environment
Tools
1 rating on this revision
Across the finish line
Assessment schedule and method are named. Evidence of completed assessments with findings tracking is what I look for.
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.