Establishes requirements for periodically assessing risk to OCSI operations, assets, and individuals — covering 3 controls per NIST SP 800-171 Rev 2.
OCSI shall periodically assess the risk to organizational operations (including mission, functions, image, reputation), organizational assets, and individuals resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. external MSSP provides independent risk assessment services as part of ongoing cybersecurity partnership.
| Control | Requirement | Implementation | Status |
|---|---|---|---|
| 3.11.1 | Periodically assess the risk to organizational operations, organizational assets, and individuals | PARTIAL. A risk assessment document exists (Risk Assessment Report) covering web application threats, data breach scenarios, and hosting risks. However, this was an AI-assisted self-assessment, not an external MSSP assessment. No prior risk assessments exist. No recurring schedule established. | Partial |
| 3.11.2 | Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified | NOT IMPLEMENTED. No vulnerability scanning tools are in use. No external MSSP performs scans. No automated scanning of any kind. No NVD monitoring process. This is a critical gap requiring a scanning tool or MSSP engagement. | Not Implemented |
| 3.11.3 | Remediate vulnerabilities in accordance with risk assessments | PARTIAL. Risk-based SLA defined (Critical: 24hr, High: 72hr, Medium: 30 days, Low: 90 days). POA&M tracks 13 open items. However, this is the first formal gap analysis — no prior vulnerability remediation cycle has been completed. | Partial |
| Risk Level | Remediation SLA | Approval Required | external MSSP Involvement |
|---|---|---|---|
| Critical | 24 hours | President + Security Officer | Immediate notification |
| High | 72 hours | Security Officer | Next-day consultation |
| Medium | 30 days | Security Officer | Quarterly review |
| Low | 90 days | Developer | Quarterly review |