NIST SP 800-171 Rev 2 · 3.12 Security Assessment
3.12.4 System security plan
Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
- SPRS weight
- none
- No point value. Without a system security plan no score can be submitted to SPRS at all, and the assessment cannot be conditioned.
- CMMC level
- L2
- Level 2 only; not among the 17 Level 1 practices.
- Assessment objectives
- 8
- From NIST SP 800-171A, each one a “determine if” an assessor answers.
What an assessor checks
NIST SP 800-171A breaks 3.12.4 into 8 objectives. Every one has to be met for the requirement to be met; a partial answer scores as not implemented.
- [a]Determine if a system security plan is developed.
- [b]Determine if the system boundary is described and documented in the system security plan.
- [c]Determine if the system environment of operation is described and documented in the system security plan.
- [d]Determine if the security requirements identified and approved by the designated authority as non-applicable are identified.
- [e]Determine if the method of security requirement implementation is described and documented in the system security plan.
- [f]Determine if the relationship with or connection to other systems is described and documented in the system security plan.
- [g]Determine if the frequency to update the system security plan is defined.
- [h]Determine if system security plan is updated with the defined frequency.
- Examine
- [SELECT FROM: Security planning policy; procedures addressing security plan development and implementation; procedures addressing security plan reviews and updates; enterprise architecture documentation; security plan; records of security plan reviews and updates; other relevant documents or records].
- Interview
- [SELECT FROM: Personnel with security planning and plan implementation responsibilities; personnel with information security responsibilities].
- Test
- [SELECT FROM: Organizational processes for security plan development, review, update, and approval; mechanisms supporting the security plan].
If it is open: POA&M eligibility
Not POA&M-eligible: blocks the assessment · 0 points deducted
Named in 170.21(a)(2)(iii), and more than that: without a system security plan there is no assessment to condition and no score to submit to SPRS. This is step one, before any technical remediation.
A POA&M is only permitted at a score of 88 or above, and closes in one 180-day window. Check a full gap list or compute your score.
Where 3.12.4 maps
NIST SP 800-53 Rev 5
- PL-1 Planning Policy
- PL-2 System Security Plan
- CA-1 Security Assessment and Authorization Policy
- CA-6 Security Authorization
- PM-1 Information Security Program Plan
- PM-2 Information Security Program Leadership Role
- PM-3 Information Security Resources
- PM-11 Mission/Business Process Definition
NIST CSF 2.0
- Organizational context is understood and informs risk management Organizational Context
- Business environment is understood Business Environment
SOC 2
- CC1 Control Environment - Commitment to integrity and ethical values
Query it from your own tools
This page and the MacTech CMMC MCP server render the same dataset. Ask your assistant and it will answer from the methodology, not from memory.
lookup_control 3.12.4 get_assessment_objectives 3.12.4 generate_poam_entries ["3.12.4"]
Install the MCP server, free, no account.
From MacZine