(4) Security Controls Assessment - Security controls
assessment is required to make sure that the security
controls implemented are functioning properly and meet the
security objectives specified. This step includes developing
a security assessment plan that defines what are the controls
to be assessed, what are the assessment methods to be used,
and what are the security metrics for each security control.
The results of the assessment process are documented in a
security assessment report. This step may result in going
back to the previous steps in case of deficiency in the
controls implemented or continuing with the next steps.