NIST SP 800-171 Rev 2 · 3.11 Risk Assessment
3.11.2 Vulnerability scanning
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
- SPRS weight
- 5
- 5 points deducted from 110 when not implemented.
- CMMC level
- L2
- Level 2 only; not among the 17 Level 1 practices.
- Assessment objectives
- 5
- From NIST SP 800-171A, each one a “determine if” an assessor answers.
What an assessor checks
NIST SP 800-171A breaks 3.11.2 into 5 objectives. Every one has to be met for the requirement to be met; a partial answer scores as not implemented.
- [a]Determine if the frequency to scan for vulnerabilities in an organizational system and its applications that process, store, or transmit CUI is defined.
- [b]Determine if vulnerability scans are performed in an organizational system that processes, stores, or transmits CUI with the defined frequency.
- [c]Determine if vulnerability scans are performed in an application that contains CUI with the defined frequency.
- [d]Determine if vulnerability scans are performed in an organizational system that processes, stores, or transmits CUI when new vulnerabilities are identified.
- [e]Determine if vulnerability scans are performed in an application that contains CUI when new vulnerabilities are identified.
- Examine
- [SELECT FROM: Risk assessment policy; procedures addressing vulnerability scanning; risk assessment; security plan; security assessment report; vulnerability scanning tools and associated configuration documentation; vulnerability scanning results; patch and vulnerability management records; other relevant documents or records].
- Interview
- [SELECT FROM: Personnel with risk assessment, security assessment and vulnerability scanning responsibilities; personnel with vulnerability scan analysis and remediation responsibilities; personnel with information security responsibilities; system or network administrators].
- Test
- [SELECT FROM: Organizational processes for vulnerability scanning, analysis, remediation, and information sharing; mechanisms supporting or implementing vulnerability scanning, analysis, remediation, and information sharing].
If it is open: POA&M eligibility
Not POA&M-eligible: above the 1-point ceiling · 5 points deducted
Worth 5 points. No requirement over 1 point may appear on a Level 2 POA&M, so this has to be closed before the assessment.
A POA&M is only permitted at a score of 88 or above, and closes in one 180-day window. Check a full gap list or compute your score.
Where 3.11.2 maps
NIST SP 800-53 Rev 5
- RA-5 Vulnerability Scanning
NIST CSF 2.0
- Cybersecurity risks are identified Risk Assessment
SOC 2
- CC3 Risk Assessment - Specify objectives and identify risks
Query it from your own tools
This page and the MacTech CMMC MCP server render the same dataset. Ask your assistant and it will answer from the methodology, not from memory.
lookup_control 3.11.2 get_assessment_objectives 3.11.2 generate_poam_entries ["3.11.2"]
Install the MCP server, free, no account.
From MacZine