- A chosen scope small enough to finish — one practice, one family, or one system, not 'everything'
- The evidence index (ATL-008), so examination starts from claimed evidence rather than from scratch
- The POA&M (ATL-006) and risk register (ATL-005), where every gap found will land
Internal Assessment Worksheet
A structured worksheet for examining your own environment against a chosen scope — a stated method, a sampling plan, item-by-item observations, and a results summary that routes every gap somewhere — so the self-check produces findings you can act on rather than reassurance you wanted.
Purpose, inputs, and completion
Purpose. Between formal assessments, an organization either examines itself or waits to be surprised. This worksheet structures the self-examination: a declared scope and method, a sample chosen before the results, factual item-by-item observations, and a summary that routes every gap into the POA&M or the risk register. Done on a rotation, it is how a small organization finds its own findings first.
When to use it. Choose a scope you can finish in a day or two — one practice, one requirement family, one system — and declare it in the header before touching anything. Sample deliberately, write what you observed rather than what you concluded, and resist the pull to soften: a gap found here costs a POA&M entry, while the same gap found by someone else costs considerably more. Rotate scopes so the whole environment gets examined across the year.
- Declare scope, method, and assessor in the header before examining anything; a scope chosen after the results is not a scope.
- Build the sampling plan before pulling items, and record how each sample was chosen — convenience samples find convenient results.
- Examine each item against what should be true, and write the observed state factually, without softening verbs.
- Mark gaps honestly, then route every one to the POA&M or the risk register — a gap that lands nowhere was found for nothing.
- Summarize results in plain language and file the worksheet with the artifacts it examined.
Evidence, validation, and failure modes
- A dated, scoped record of self-examination with a stated method and sample
- Item-level observations a later reviewer can retrace
- A routing record connecting every gap found to a tracked entry elsewhere in the library
- Re-pull one sampled item and repeat its examination from the worksheet's own description; a different result means the observation was written too vaguely to be evidence.
- Follow every gap marked Y to its routed destination; any gap with no POA&M or risk-register entry behind it has evaporated, which defeats the exercise.
- The operator examines their own work and finds it excellent — where headcount allows, separate the examiner from the operator, and where it does not, sample harder.
- Samples chosen for availability: the three newest laptops, the tidiest project folder, the one well-run system — a sample designed to pass.
- Observations written as conclusions ('access control is fine') instead of facts ('4 of 25 sampled accounts had no MFA enrollment'), leaving nothing to retrace.
Practices and requirements this artifact relates to
Brilliant at the Basics practices
NIST SP 800-171 Rev. 2
NIST SP 800-171 Rev. 3
Relationships are mapped support, not equivalence: completing this artifact documents work relevant to these requirements and does not by itself address any of them. Retention: Retain each completed worksheet for at least three years alongside the POA&M and risk-register entries it produced; the series of worksheets is the record of a program examining itself.
Preview — exactly what prints
Internal Assessment Worksheet
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
Between formal assessments, an organization either examines itself or waits to be surprised. This worksheet structures the self-examination: a declared scope and method, a sample chosen before the results, factual item-by-item observations, and a summary that routes every gap into the POA&M or the risk register. Done on a rotation, it is how a small organization finds its own findings first.
How to use it
Choose a scope you can finish in a day or two — one practice, one requirement family, one system — and declare it in the header before touching anything. Sample deliberately, write what you observed rather than what you concluded, and resist the pull to soften: a gap found here costs a POA&M entry, while the same gap found by someone else costs considerably more. Rotate scopes so the whole environment gets examined across the year.
Assessment header
Filled in before examination begins. The header is the fence that keeps the results honest.
Header
| Scope (what is being examined) | Method (examine / interview / test — which and how) | Date(s) performed | Assessor (name, role, relationship to the systems examined) | Boundary document version referenced |
|---|---|---|---|---|
This worksheet is an internal look at your own environment. It is not an assessment under NIST SP 800-171, CMMC, or any other framework or methodology; it produces no score, confers no status, and its results are not comparable to any official assessment's. Its value is earlier knowledge of your own gaps — nothing more, and nothing less.
Sampling plan
Decide what you will look at — and how you chose it — before you look. The 'why this sample' column is what separates examination from theater.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Population | Sample size and how chosen | Items selected | Why this sample |
|---|---|---|---|
| EXAMPLE: All user accounts in the cloud tenant (74) | 25, every third account from an alphabetical export | Listed in working notes, filed with this worksheet | Mechanical selection removes the temptation to pick accounts known to be clean |
Per-item examination
One row per item examined. Observed state is a fact a stranger could re-verify — numbers, dates, and settings, not adjectives.
Rows beginning EXAMPLE: show the expected shape — replace them with your own.
| Item examined | What was checked | Observed state | Gap (Y/N) | Note |
|---|---|---|---|---|
| EXAMPLE: Sampled accounts (25 of 74) | MFA enrollment and method per account | 21 enrolled with phishing-resistant method; 4 with no enrollment (3 service accounts, 1 new hire) | Y | Service-account handling has no documented pattern — routed below |
Results summary and routing
Plain-language totals, and a destination for every gap. This section is what the executive sponsor reads.
Summary
| Items examined (count) | Gaps found (count) | One-paragraph summary of what was learned | Themes worth watching (even where no gap was marked) |
|---|---|---|---|
Gap routing
| Gap (from the table above) | Routed to (POA&M ID / risk register ID) | Owner | Date routed |
|---|---|---|---|
Close the loop at the next run: begin by checking whether the previous worksheet's routed gaps actually moved. A self-examination program whose findings never move is measuring its own paperwork.
Document control, version history, and approval
An artifact without an owner, a review date, and an approval trail is a snapshot, not a record. Complete this section before the document is used, and update it at every review.
| Field | Entry |
|---|---|
| Document owner (named person) | |
| Suggested owner role | IT leader or compliance lead |
| Approval authority | Executive sponsor |
| Review frequency | Run at least semiannually, rotating scope so the whole environment is examined across a year; the worksheet format itself reviewed annually |
| Next scheduled review | |
| Storage location of the completed document | |
| Retention | Retain each completed worksheet for at least three years alongside the POA&M and risk-register entries it produced; the series of worksheets is the record of a program examining itself. |
Version history
| Version | Date | Author | Summary of change | Approved by |
|---|---|---|---|---|
Review and approval
| Reviewed by | Role | Date | Signature / initials |
|---|---|---|---|
Fill this in inside your own environment, not on any public website or unapproved cloud tool. A completed copy may reveal your security posture: never include CUI, export-controlled data, credentials or keys, unremediated vulnerability details, network diagrams, or customer-sensitive information beyond what the artifact strictly needs, and store the completed document with the same care as the systems it describes.
This is independent educational material. Completing it documents your work and produces records a reviewer can examine — it does not, by itself, implement a safeguard, satisfy any NIST SP 800-171 requirement, establish compliance with DFARS or CMMC, or replace your own analysis within your defined system boundary. Requirement references are mapped relationships, not equivalence claims. Tailor every section to your technical, operational, contractual, regulatory, and safety requirements.