This objective requires your organization to identify and plan the assessments needed to evaluate how effectively your security controls are implemented and operating—especially those that protect Controlled Unclassified Information (CUI). These may include internal assessments, third-party audits, or control-specific tests.