3.12 Security Assessment5 pts

3.12.1 — Test your controls

Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.

You periodically check that your controls actually work.

What it actually means

Don't assume your controls work — verify them periodically. A self-assessment against the 110 requirements (which is what generates your SPRS score) is exactly this. The point is to confirm controls are effective in practice, not just configured.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Security Assessment (3.12)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.