CA-3 — Information Exchange
System information exchange requirements apply to information exchanges between two or more systems. System information exchanges include connections via leased lines or virtual private networks, connections to internet service providers, database sharing or exchanges of database transaction information, connections and exchanges with cloud services, exchanges via web-based services, or exchanges of files via file transfer protocols, network protocols (e.g., IPv4, IPv6), email, or other organization-to-organization communications. Organizations consider the risk related to new or increased threats that may be introduced when systems exchange information with other systems that may have different security and privacy requirements and controls. This includes systems within the same organization and systems that are external to the organization. A joint authorization of the systems exchangi
Read the official statement, discussion, parameters, enhancements, and assessment methods →
NIST CSF 2.0 informative references
These CSF Subcategories list this base control or one of its enhancements in the imported NIST informative reference.
NIST SP 800-171 and SP 800-172
SP 800-171 requirements sourcing this control
SP 800-172 enhanced requirements sourcing this control
MITRE D3FEND techniques
MITRE ATT&CK relationships
Curated mitigation mappings
Inferred behavior relationships
Experimental: These relationships are inferred through D3FEND and must be validated against architecture, telemetry, and threat context.
Use the map without overclaiming.
A CSF informative reference is not an equivalence statement. A source-control relationship is not proof of implementation. A D3FEND semantic relationship is not a product claim. An inferred ATT&CK link is a hypothesis for engineering analysis.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.