This objective ensures your organization has formally documented which assessments will be performed, how often, and by whom. These assessments must be clearly defined in your policies, procedures, or security plans to demonstrate your ongoing evaluation of controls protecting Controlled Unclassified Information (CUI).