{
  "title": "NIST SP 800-171&#58; How to Perform a Self-Assessment",
  "date": "2021-08-09",
  "author": "Lakeridge Technologies",
  "featured_image": "/assets/images/blog/2021/08/working_pc.jpg",
  "content": {
    "full_html": "<h2>Why Perform a Self-Assessment?</h2>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tThere are multiple reasons why an organization will want to perform a NIST SP 800-171 self-assessment and generate an SPRS score. Whatever the specific reason it stems from one requirement, DFARS clause 252.204-7019 “Notice of NIST SP 800-171 DoD Assessment Requirements”. This contract clause requires organizations to assess their implementation of NIST SP 800-171 security controls.\n\t</div>\n</div>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img src=\"/assets/images/blog/2021/08/pentagon_image.jpg\" alt=\"test\" class=\"img-fluid blog-img\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tIn general, sub contractors are informed by their prime contractor that they need to perform a “basic” self-assessment or a prime contractor is notified by their DoD point of contact of this requirement.\n\t</div>\n</div>\n\n<h2>How to Perform a Self-Assessment</h2>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tPerforming a NIST SP 800-171 is no easy task. It requires knowledge of IT systems, an understanding of NIST SP 800-171 cybersecurity controls, and a lot of hours. Lucky for you, we have developed the Compliance Accelerator that performs your NIST SP 800-171 self-assessment. We offer a <a href=\"https://app.lakeridge.io/register\">free trial</a> for you to give it a spin.\n\t</div>\n</div>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img src=\"/assets/images/blog/2021/08/lakeridge_app_dashboard.png\" alt=\"test\" class=\"img-fluid blog-img\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tSo how does it work?\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tIn the application you simply answer yes or no questions for each of the NIST SP 800-171 security controls and click submit for assessment. It will then inform you if you are meeting the requirement or not and it will update your SPRS score automatically.\n\t</div>\n</div>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img src=\"/assets/images/blog/2021/08/lakeridge_app_nist_800_171_gap_analysis.png\" alt=\"test\" class=\"img-fluid blog-img\">\n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tIf you are not meeting the requirements it will provide you tasks to complete for you to meet the requirement. After you complete the tasks it will mark the security control as “Audit Ready” and update your SPRS score. Once you complete all of the questions and tasks you will achieve a perfect SPRS score of 110.\n\t</div>\n</div>\n\n<div class=\"row mb-4 text-center\">\n\t<div class=\"col\">\n\t\t<img src=\"/assets/images/blog/2021/08/lakeridge_app_tasks.png\" alt=\"test\" class=\"img-fluid blog-img\">\n\t</div>\n</div>\n\n<h2>Having a System Security Plan is Critical</h2>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tKeep in mind that performing a self-assessment and generating an SPRS score is not the only requirement an organization has as part of DFARS clause 252.204-7019. The organization must also have a system security plan otherwise the score you generated doesn’t count. \n\t</div>\n</div>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\t“Since the NIST SP 800-171 DoD Assessment scoring methodology is based on the review of a system security plan describing how the security requirements are met, it is not possible to conduct the assessment if the information is not available. The absence of a system security plan would result in a finding that ‘an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.”\n\t</div>\n</div>\n\n<h2>How do you create a System Security Plan?</h2>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tOur Compliance Accelerator application includes a system security plan template that you can use to describe how your organization has implemented it’s NIST SP 800-171 security controls. You can use the guidance from within the tool to help fill out your system security plan. If you have not implemented all of your security controls you will need a plan of action and milestones document to describe how you plan to implement them. You can use the tasks generated in the app along with our plan of action and milestones template to accomplish this.\n\t</div>\n</div>\n\n<h2>Submitting the Self-Assessment to the DoD</h2>\n\n<div class=\"row mb-4\">\n\t<div class=\"col\">\n\t\tAfter generating your SPRS score and system security plan you will need to submit the score to the DoD. Please read page 21 of the NIST SP 800-171 Assessment Methodology document for instructions on how to accomplish this.\n\t</div>\n</div>\n",
    "plain_text": "Why Perform a Self-Assessment?\n\n\n\t\n\t\tThere are multiple reasons why an organization will want to perform a NIST SP 800-171 self-assessment and generate an SPRS score. Whatever the specific reason it stems from one requirement, DFARS clause 252.204-7019 “Notice of NIST SP 800-171 DoD Assessment Requirements”. This contract clause requires organizations to assess their implementation of NIST SP 800-171 security controls.\n\t\n\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\t\tIn general, sub contractors are informed by their prime contractor that they need to perform a “basic” self-assessment or a prime contractor is notified by their DoD point of contact of this requirement.\n\t\n\n\nHow to Perform a Self-Assessment\n\n\n\t\n\t\tPerforming a NIST SP 800-171 is no easy task. It requires knowledge of IT systems, an understanding of NIST SP 800-171 cybersecurity controls, and a lot of hours. Lucky for you, we have developed the Compliance Accelerator that performs your NIST SP 800-171 self-assessment. We offer a free trial for you to give it a spin.\n\t\n\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\t\tSo how does it work?\n\t\n\n\n\n\t\n\t\tIn the application you simply answer yes or no questions for each of the NIST SP 800-171 security controls and click submit for assessment. It will then inform you if you are meeting the requirement or not and it will update your SPRS score automatically.\n\t\n\n\n\n\t\n\t\t\n\t\n\n\n\n\t\n\t\tIf you are not meeting the requirements it will provide you tasks to complete for you to meet the requirement. After you complete the tasks it will mark the security control as “Audit Ready” and update your SPRS score. Once you complete all of the questions and tasks you will achieve a perfect SPRS score of 110.\n\t\n\n\n\n\t\n\t\t\n\t\n\n\nHaving a System Security Plan is Critical\n\n\n\t\n\t\tKeep in mind that performing a self-assessment and generating an SPRS score is not the only requirement an organization has as part of DFARS clause 252.204-7019. The organization must also have a system security plan otherwise the score you generated doesn’t count. \n\t\n\n\n\n\t\n\t\t“Since the NIST SP 800-171 DoD Assessment scoring methodology is based on the review of a system security plan describing how the security requirements are met, it is not possible to conduct the assessment if the information is not available. The absence of a system security plan would result in a finding that ‘an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.”\n\t\n\n\nHow do you create a System Security Plan?\n\n\n\t\n\t\tOur Compliance Accelerator application includes a system security plan template that you can use to describe how your organization has implemented it’s NIST SP 800-171 security controls. You can use the guidance from within the tool to help fill out your system security plan. If you have not implemented all of your security controls you will need a plan of action and milestones document to describe how you plan to implement them. You can use the tasks generated in the app along with our plan of action and milestones template to accomplish this.\n\t\n\n\nSubmitting the Self-Assessment to the DoD\n\n\n\t\n\t\tAfter generating your SPRS score and system security plan you will need to submit the score to the DoD. Please read page 21 of the NIST SP 800-171 Assessment Methodology document for instructions on how to accomplish this.\n\t\n\n"
  },
  "metadata": {
    "description": null,
    "permalink": "/how-to-perform-a-nist-sp-800-171-self-assessment.json",
    "categories": [],
    "tags": []
  }
}