← All seven chapters

ASSESS · RMF LIFECYCLE

Assess

How do we know the controls work?

We’ve described how the controls are supposed to work. Now let’s put those claims under some scrutiny. What would convince us that a protection works? What might show that it doesn’t? Assessment gets much more useful when everyone understands the question being tested and is willing to learn from the answer.

NIST’s Assess guidance looks at whether controls are correctly implemented, function as intended, and deliver the required security and privacy outcomes. It includes assessment planning, reporting, remediation, and updates to the plans. NIST’s Assess step describes the expected outcomes.

Assess / Visual guideUse evidence to reach a supported conclusion.
Agreed objectives, scope, and procedures
ExamineReview records and other assessment objects.
InterviewDiscuss responsibilities and operation.
TestCompare observed and expected behavior.
Evidence-supported findingsRecord results, limitations, and weaknesses; remediate and retest as appropriate.

Choose methods and coverage for the assessment objectives; the diagram does not prescribe a fixed test sequence.

Agree on what a useful assessment will answer

Start with the assessment objectives, scope, procedures, and required level of assessor independence. Identify the evidence to examine, the people to interview, and the mechanisms or activities to test. Get the assessment plan reviewed and approved through the applicable process before relying on the results.

Talk about sampling and limitations up front. Which parts of the implementation will the assessment cover? What period will the records represent? What could remain untested? These choices affect what a conclusion can reasonably tell us. Agreeing on them early also gives control owners a fair understanding of what they need to make available.

Follow the claim to the evidence

A procedure can explain the intended process. An interview can help establish how someone carries it out. A test or operational record can show what happens under the conditions examined. Use the assessment methods that answer the control’s objectives, and investigate when the different sources tell different stories.

Ask what a result actually proves. A passing test has a scope and a set of conditions. A tool report may cover only part of a requirement. Keep conclusions tied to the evidence, and make missing information visible. “We haven’t established that yet” can be a more useful answer than confidence that the assessment hasn’t earned.

Use findings to improve the decision

Describe the requirement, what was observed, and the evidence supporting the finding. Give the system owner enough detail to understand the issue and evaluate a response. Discuss limitations and residual uncertainty alongside the findings so the next decision reflects what is actually known.

When a fix is made, reassess the affected implementation and record the result. Preserve the earlier findings so someone can follow what changed. Update the system description and the plans, and track unresolved work through the applicable corrective-action process. Finding a problem is useful; following it through is what makes the assessment improve the system.

How this applies on SAP networks

NIST gives us the assessment question: does the implemented control achieve the required outcome? JSIG directs how that assessment is planned and carried out for SAP systems. The security control assessor approves the assessment plan, findings are documented, and reassessment preserves the original results alongside the updates. The implementation instructions and the assessment evidence should tell a consistent story about what was required, what was done, and what the assessment established. 2016 JSIG §2.3.4 gives the SAP-specific instructions for this step.

Let’s talk it through

Pick a question and compare how you’d approach it. Ask what information would change your answer.

  • What evidence would make us reconsider a control we currently believe is effective?
  • If the procedure, interview, and test result disagree, what would we investigate next?
  • Which conclusion has the most uncertainty, and how could that uncertainty affect the authorization decision?

What do we carry forward?

Carry supported findings, remediation results, unresolved issues, and their risk implications into Authorize. The decision-maker needs to understand what was assessed and where uncertainty remains, including what a promised fix has yet to demonstrate.

The Assess section of Body of Evidence & Artifacts connects this work to the artifacts and body of evidence (BOE) you produce and maintain.