Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: CHAPTER THREE: THE REQUIREMENTS > 3.2   Developing security and privacy assessment plans

3.2.6   Finalize assessment plan and obtain approval to execute plan.

Scroll Prev Top Next More

After selecting the assessment procedures (including developing necessary procedures not contained in the Special Publication 800-53A catalog of procedures), tailoring the procedures for information system/platform-specific and organization-specific conditions, optimizing the procedures for efficiency, and addressing the potential for unexpected events impacting the assessment, the assessment plan is finalized, and the schedule is established including key milestones for the assessment process. Once the security assessment plan or privacy assessment plan is completed, the plan is reviewed and approved by appropriate organizational officials35 to ensure that the plan is: (i) complete; (ii) consistent with the security or privacy objectives of the organization, as appropriate, and the organization’s assessment of risk; and (iii) cost-effective with regard to the resources allocated for the assessment.

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056