Twenty-two nuggets ago, this series started with knowing your CUI. Since then we’ve built out governance, architecture, access, six protection domains, and detection capability. This is the last stop, and fittingly, it’s about checking your own work before someone else does.
An internal audit is a dress rehearsal. You run the full show, in the actual space, under something close to real conditions, specifically so you find the missed cue and the wobbly set piece while it’s still just you in the room. Nobody wants opening night to be the first time they discover the problem. That’s what the Security Assessment (CA) family exists to formalize, and it’s also where we’re closing a loop that’s been open since Nugget #21.
CA.L2-3.12.1: Periodically Assess the Security Controls
We touched on this in Nugget #5 but expand upon it here in the last issue.
Periodically (not less than annually) assess the security controls in organizational systems to determine if the controls are effective in their application
This is the full run-through: systematically checking whether your implemented controls are actually working, not just present.
Common practices:
- Internal audits and self-assessments reviewing policies, procedures, and control implementations on a regular schedule
- Third-party security audits and penetration tests providing an outside perspective your own team can’t fully replicate
- Gap analysis against NIST SP 800-171 or a comparable framework to confirm every required control is genuinely implemented, not just claimed
- Compliance checklists or tooling applied consistently across all systems, not just the ones easiest to check
CA.L2-3.12.2: Develop and Implement Plans of Action
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems
Here’s the control that’s easy to lose track of in a nugget about audits, and it’s the one that actually matters most. A dress rehearsal that finds problems and then does nothing about them wasn’t worth running. This is your POA&M requirement: every deficiency your internal audits (CA.L2-3.12.1), continuous monitoring (CA.L2-3.12.3, next), and risk assessments (RA.L2-3.11.1, see below) turn up needs to feed into a documented plan of action with owners and timelines, not just a list of things everyone agrees are problems.
The POA&M got its full dedicated treatment back in Nugget #4, where we covered SSP, POA&M, SPRS, and Annual Affirmation together as the governance foundation the rest of the series builds on. Worth the callback here specifically because this is where the POA&M actually gets used in practice: it’s the destination for everything this nugget’s audit activities uncover. An audit program that finds issues and a POA&M process that tracks them to closure are two halves of the same requirement. Neither one works alone.
CA.L2-3.12.3: Monitor Security Controls on an Ongoing Basis
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls
If 3.12.1 is the scheduled dress rehearsal, this is the stage manager watching every performance after opening night too. Controls that were effective at implementation can quietly stop being effective as your environment changes.
Common practices:
- SIEM tools continuously watching logs, events, and alerts for anomalies (this is the same correlation capability discussed under AU.L2-3.3.5 in Nugget #20, doing double duty here)
- Automated patch management keeping systems current so control effectiveness doesn’t erode through neglect
- Network and endpoint monitoring (IDS, EDR) catching unauthorized access or suspicious activity as it happens
- Continuous vulnerability scanning, tying directly back to RA.L2-3.11.2 in Nugget #21
The Risk Assessment Connection
RA.L2-3.11.1: Periodically assess the risk to organizational operations, assets, and individuals
We gave this control its full treatment in Nugget #21 as the foundation the entire vulnerability management program depends on. Worth a callback here rather than a repeat: risk assessment identifies what could go wrong, this nugget’s CA controls verify whether your defenses actually hold up, and CA.L2-3.12.2 is where anything that doesn’t hold up gets a documented plan to fix it. Three controls, two families, one continuous loop.
The Fourth CA Control
There’s a fourth control in this family worth naming for completeness: CA.L2-3.12.4, developing, documenting, and periodically updating your System Security Plan. Like the POA&M, this got its dedicated treatment in Nugget #4 as part of the governance foundation. It belongs to the CA family alongside the three controls above, but it earns a full nugget of its own rather than a paragraph here.
Common Failures Across This Control Set
CA.L2-3.12.1 Internal audits performed but findings never formally documented or tracked
CA.L2-3.12.2 Deficiencies identified through audits or monitoring never make it into a POA&M
CA.L2-3.12.3 Continuous monitoring tools deployed but alerts not actively reviewed
RA.L2-3.11.1 Risk assessment treated as a one-time exercise instead of a recurring one
SSP Mapping Note
All four CA controls belong under Security Assessment in your SSP, with CA.L2-3.12.4 itself being the document you’re maintaining. RA.L2-3.11.1 belongs under Risk Assessment, a separate family, even though it’s functionally the starting point for this nugget’s entire audit cycle.
For each control your SSP should document:
- The specific audit methodology, tools, and monitoring platforms in use
- The policy governing assessment frequency and POA&M timelines by severity
- Who owns each phase, assessment, monitoring, and POA&M tracking, don’t assume it’s the same person
- How you’ll demonstrate a closed loop: finding, documentation, remediation, verification
That’s the series. Twenty-three nuggets encompassing one continuous thread from knowing your CUI to auditing whether everything you built to protect it is actually working. If your dress rehearsal is turning up more questions than answers, that’s exactly what it’s supposed to do, and it’s a much better place to find them than in front of an assessor. Contact DTC’s C3PAO team whenever you’re ready to talk through what your internal audit is telling you.
Thanks for following along through all twenty-three. We will revisit these when NIST SP 800-171 Rev 3 finds its way into CMMC. STAY TUNED!!