RA.L2-3.11.2[c]: Prove That You’re Following Through on Your Risk Response Plans

Mapped to NIST 800-171 Requirement: 3.11.2
CMMC Assessment Objective: RA.L2-3.11.2[c]

What This Control Means
This control moves from planning to execution.
You must show that:
• Mitigation plans are in progress or completed
• Accepted risks are acknowledged and justified
• Transferred risks are documented via contracts or SLAs
• Avoided risks have been addressed by altering business practices or technologies
Plans are important—but action is essential.

Why It Matters
If you document risk responses but never follow through:
• CUI remains vulnerable to known threats
• POA&M items go unresolved
• Risk scores remain artificially low
• Auditors may view your risk management program as non-compliant
Implementation turns policy into real-world protection.

How to Implement It
1. Track All Risk Responses
• Use your risk register and POA&M to show progress
• Log completion dates and updates for mitigation actions
2. Show Supporting Documentation
• For mitigation:
◦ Screenshots, configuration files, or change logs
• For acceptance:
◦ Formal acceptance sign-offs by leadership
• For transfer:
◦ Vendor contracts, cyber insurance policies
• For avoidance:
◦ Business practice or scope changes
3. Review Periodically
• Follow up on risks with outstanding actions
• Adjust strategies if implementation isn’t effective
4. Assign Accountability
• Ensure every response has an owner
• Set deadlines and escalate if timelines slip

Evidence the Assessor Will Look For
• POA&M updates showing completed or in-progress mitigation
• Risk register with response status and action logs
• Documents showing vendor acceptance of transferred risk
• Screenshots, emails, or change records tied to mitigation efforts
• Formal records of risk acceptance decisions

Common Gaps
• Risk responses are planned but never acted on
• No evidence of completed POA&M items
• Mitigation deadlines missed with no updates
• Transferred risks have no supporting contracts or documentation

How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Tracking implementation of risk responses through your POA&M and risk register
• Assigning owners, deadlines, and progress notes to each response
• Logging evidence of completed actions (e.g., uploaded screenshots, signed approvals)
• Integrating with ticketing or project management tools for workflow visibility
• Ensuring every risk decision leads to real-world follow-through
With Cuick Trac, your risk response isn’t just documented—it’s delivered.

Final CTA
Security isn’t what you say you’ll do—it’s what you actually do.
Schedule a Cuick Trac demo to prove your risk responses are implemented and protecting your CUI.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.