Assessment Criteria for NIST 800-171 and NIST 800-53
Learn about NIST 800-53A and NIST 800-171A - the assessment criteria for CMMC and FedRamp.
Written By Micah
NIST publishes assessment objectives to assist internal and external assessors when auditing NIST frameworks. If you are using either NIST 800-171 or NIST 800-53 in your compliance program (to meet CMMC or FedRamp requirements), the content in these documents can serve as additional resources as you prepare to meet framework requirements.
The documents list each NIST requirement and its corresponding assessment objectives. These objectives can include any combination of examinations, interviews, and tests.
For example, the ‘Examine’ options for Access Control - 03.01.01.0, below, offers a selection of documents that can be used to demonstrate the framework requirement: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems)”.
(extracted from NIST SP 800-171A):
The assessment criteria for each framework are on the NIST website: