3.11.1 ๐๐๐ซ๐ข๐จ๐๐ข๐๐๐ฅ๐ฅ๐ฒ ๐๐ฌ๐ฌ๐๐ฌ๐ฌ ๐ซ๐ข๐ฌ๐ค…
This is the fourth-most “Other than satisfied” #CMMC requirement.
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
Not hard to do, but often misunderstood.
Let’s break it down.
๐๐๐ซ๐ข๐จ๐๐ข๐๐๐ฅ๐ฅ๐ฒ = at least once a year
๐๐ฌ๐ฌ๐๐ฌ๐ฌ ๐ญ๐ก๐ ๐ซ๐ข๐ฌ๐ค = the assessor expectation for assessing risk is higher than these three words describe. Refer to NIST Special Publication 800-30 and NIST SP 800-39.
The key components of assessing risk are:
๐ท ๐ identify your critical assets and functions (such as your CUI)
๐ what threats exist for those assets?
๐ช how would the threats attack those assets?
๐ what makes the asset vulnerable to the threat?
๐ if there was no mitigation in place to prevent the threat, what impact would occur?
๐ฎ what are you doing to mitigate the threat now?
โณ how likely is the threat to occur (with current mitigations)?
๐ธ what impact (with current mitigations)?
โ๏ธ what is the resulting risk #?
๐ what do you propose to mitigate further (or risk accept)?
๐
if you did this proposed mitigation, what is the new likelihood?
๐ if you did this proposed mitigation, what is the new impact?
โ๏ธ new risk #
๐ญ๐ก๐ ๐๐ซ๐๐ช๐ฎ๐๐ง๐๐ฒ ๐ข๐ฌ ๐๐๐๐ข๐ง๐๐ = write down how often you do risk assessments! (see ‘periodically’ above)
๐จ๐ซ๐ ๐๐ง๐ข๐ณ๐๐ญ๐ข๐จ๐ง๐๐ฅ ๐จ๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง๐ฌ (๐ข๐ง๐๐ฅ๐ฎ๐๐ข๐ง๐ ๐ฆ๐ข๐ฌ๐ฌ๐ข๐จ๐ง, ๐๐ฎ๐ง๐๐ญ๐ข๐จ๐ง๐ฌ, ๐ข๐ฆ๐๐ ๐, ๐จ๐ซ ๐ซ๐๐ฉ๐ฎ๐ญ๐๐ญ๐ข๐จ๐ง), ๐จ๐ซ๐ ๐๐ง๐ข๐ณ๐๐ญ๐ข๐จ๐ง๐๐ฅ ๐๐ฌ๐ฌ๐๐ญ๐ฌ, ๐๐ง๐ ๐ข๐ง๐๐ข๐ฏ๐ข๐๐ฎ๐๐ฅ๐ฌ = NIST is kind enough to give you a list of assets to consider.
๐ซ๐๐ฌ๐ฎ๐ฅ๐ญ๐ข๐ง๐ ๐๐ซ๐จ๐ฆ ๐ญ๐ก๐ ๐จ๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง ๐จ๐ ๐๐ง ๐จ๐ซ๐ ๐๐ง๐ข๐ณ๐๐ญ๐ข๐จ๐ง๐๐ฅ ๐ฌ๐ฒ๐ฌ๐ญ๐๐ฆ ๐ญ๐ก๐๐ญ ๐ฉ๐ซ๐จ๐๐๐ฌ๐ฌ๐๐ฌ, ๐ฌ๐ญ๐จ๐ซ๐๐ฌ, ๐จ๐ซ ๐ญ๐ซ๐๐ง๐ฌ๐ฆ๐ข๐ญ๐ฌ ๐๐๐ = the risk assessment has to include in-scope information system.
๐๐ก๐ ๐๐๐๐ ๐จ๐ ๐ซ๐๐ช๐ฎ๐ข๐ซ๐๐ฆ๐๐ง๐ญ 3.11.1 ๐ข๐ฌ ๐ญ๐จ ๐ ๐๐ญ ๐๐จ๐ฆ๐ฉ๐๐ง๐ข๐๐ฌ ๐ญ๐จ
1) consider what risks their organization and their CUI faces;
2) decide which risks cannot be accepted
3) apply mitigations to reduce risk.
But an assessor will generally only require evidence that you’ve considered what risk your organization and CUI faces (the first part).
๐๐ญ๐ก๐๐ซ ๐ญ๐ก๐ข๐ง๐ ๐ฌ ๐ญ๐ก๐๐ญ ๐๐๐ง๐๐๐ข๐ญ ๐๐ซ๐จ๐ฆ ๐ซ๐ข๐ฌ๐ค ๐๐ฌ๐ฌ๐๐ฌ๐ฌ๐ฆ๐๐ง๐ญ๐ฌ:ย ย
Contractor Risk Managed Assets. Specialized Assets. Plan of Action. DFARS 252.204-7012 (b)(3). If you don’t know why I reference these, you should find out!
Shameless plug: The Kieri Compliance Documentation (Google it if curious) includes detailed instructions and a partially pre-filled-in template for Risk Assessment. We identified 28 risks that affect almost all small businesses and pre-filled them in to get you started.