Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

CA — Assessment, Authorization, and Monitoring

Study this control family as a connected set of risk outcomes, implementation decisions, evidence expectations, and assessment questions.

9Base controls
23Enhancements
32Family records
7Withdrawn records

Control family

Assessment, Authorization, and Monitoring

Use the family as a planning boundary, but assess each selected control against the system context, inherited services, organization-defined parameters, and evidence available from real operations.

9 base controls23 enhancementsRelease 5.2.0
CA

Family catalog

Search Assessment, Authorization, and Monitoring controls.

Base controls open full profiles. Enhancement results link directly to the corresponding enhancement section on the parent control page.

CA-1control

Policy and Procedures

Assessment, authorization, and monitoring policy and procedures address the controls in the CA family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that sec

CA-2control

Control Assessments

Organizations ensure that control assessors possess the required skills and technical expertise to develop effective assessment plans and to conduct assessments of system-specific, hybrid, common, and program management controls, as appropriate. The required skills include general knowledge of risk management concepts and approaches as well as comprehensive

CA-3control

Information Exchange

System information exchange requirements apply to information exchanges between two or more systems. System information exchanges include connections via leased lines or virtual private networks, connections to internet service providers, database sharing or exchanges of database transaction information, connections and exchanges with cloud services, exchang

CA-5control

Plan of Action and Milestones

Plans of action and milestones are useful for any type of organization to track planned remedial actions. Plans of action and milestones are required in authorization packages and subject to federal reporting requirements established by OMB.

CA-6control

Authorization

Authorizations are official management decisions by senior officials to authorize operation of systems, authorize the use of common controls for inheritance by organizational systems, and explicitly accept the risk to organizational operations and assets, individuals, other organizations, and the Nation based on the implementation of agreed-upon controls. Au

CA-7control

Continuous Monitoring

Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls

CA-8control

Penetration Testing

Penetration testing is a specialized type of assessment conducted on systems or individual system components to identify vulnerabilities that could be exploited by adversaries. Penetration testing goes beyond automated vulnerability scanning and is conducted by agents and teams with demonstrable skills and experience that include technical expertise in netwo

CA-9control

Internal System Connections

Internal system connections are connections between organizational systems and separate constituent system components (i.e., connections between components that are part of the same system) including components used for system development. Intra-system connections include connections with mobile devices, notebook and desktop computers, tablets, printers, cop

CA-2(1)enhancement

Independent Assessors

Independent assessors or assessment teams are individuals or groups who conduct impartial assessments of systems. Impartiality means that assessors are free from any perceived or actual conflicts of interest regarding the development, operation, sustainment, or management of the systems under assessment or the determination of control effectiveness. To achie

CA-2(2)enhancement

Specialized Assessments

Organizations can conduct specialized assessments, including verification and validation, system monitoring, insider threat assessments, malicious user testing, and other forms of testing. These assessments can improve readiness by exercising organizational capabilities and indicating current levels of performance as a means of focusing actions to improve se

CA-2(3)enhancement

Leveraging Results from External Organizations

Organizations may rely on control assessments of organizational systems by other (external) organizations. Using such assessments and reusing existing assessment evidence can decrease the time and resources required for assessments by limiting the independent assessment activities that organizations need to perform. The factors that organizations consider in

CA-3(6)enhancement

Transfer Authorizations

To prevent unauthorized individuals and systems from making information transfers to protected systems, the protected system verifies—via independent means— whether the individual or system attempting to transfer information is authorized to do so. Verification of the authorization to transfer information also applies to control plane traffic (e.g., routing

CA-3(7)enhancement

Transitive Information Exchanges

Transitive or "downstream" information exchanges are information exchanges between the system or systems with which the organizational system exchanges information and other systems. For mission-essential systems, services, and applications, including high value assets, it is necessary to identify such information exchanges. The transparency of the controls

CA-5(1)enhancement

Automation Support for Accuracy and Currency

Using automated tools helps maintain the accuracy, currency, and availability of the plan of action and milestones and facilitates the coordination and sharing of security and privacy information throughout the organization. Such coordination and information sharing help to identify systemic weaknesses or deficiencies in organizational systems and ensure tha

CA-6(1)enhancement

Joint Authorization — Intra-organization

Assigning multiple authorizing officials from the same organization to serve as co-authorizing officials for the system increases the level of independence in the risk-based decision-making process. It also implements the concepts of separation of duties and dual authorization as applied to the system authorization process. The intra-organization joint autho

CA-6(2)enhancement

Joint Authorization — Inter-organization

Assigning multiple authorizing officials, at least one of whom comes from an external organization, to serve as co-authorizing officials for the system increases the level of independence in the risk-based decision-making process. It implements the concepts of separation of duties and dual authorization as applied to the system authorization process. Employi

CA-7(1)enhancement

Independent Assessment

Organizations maximize the value of control assessments by requiring that assessments be conducted by assessors with appropriate levels of independence. The level of required independence is based on organizational continuous monitoring strategies. Assessor independence provides a degree of impartiality to the monitoring process. To achieve such impartiality

CA-7(3)enhancement

Trend Analyses

Trend analyses include examining recent threat information that addresses the types of threat events that have occurred in the organization or the Federal Government, success rates of certain types of attacks, emerging vulnerabilities in technologies, evolving social engineering techniques, the effectiveness of configuration settings, results from multiple c

CA-7(4)enhancement

Risk Monitoring

Risk monitoring is informed by the established organizational risk tolerance. Effectiveness monitoring determines the ongoing effectiveness of the implemented risk response measures. Compliance monitoring verifies that required risk response measures are implemented. It also verifies that security and privacy requirements are satisfied. Change monitoring ide

CA-7(5)enhancement

Consistency Analysis

Security and privacy controls are often added incrementally to a system. As a result, policies for selecting and implementing controls may be inconsistent, and the controls could fail to work together in a consistent or coordinated manner. At a minimum, the lack of consistency and coordination could mean that there are unacceptable security and privacy gaps

CA-7(6)enhancement

Automation Support for Monitoring

Using automated tools for monitoring helps to maintain the accuracy, currency, and availability of monitoring information which in turns helps to increase the level of ongoing awareness of the system security and privacy posture in support of organizational risk management decisions.

CA-8(1)enhancement

Independent Penetration Testing Agent or Team

Independent penetration testing agents or teams are individuals or groups who conduct impartial penetration testing of organizational systems. Impartiality implies that penetration testing agents or teams are free from perceived or actual conflicts of interest with respect to the development, operation, or management of the systems that are the targets of th

CA-8(2)enhancement

Red Team Exercises

Red team exercises extend the objectives of penetration testing by examining the security and privacy posture of organizations and the capability to implement effective cyber defenses. Red team exercises simulate attempts by adversaries to compromise mission and business functions and provide a comprehensive assessment of the security and privacy posture of

CA-8(3)enhancement

Facility Penetration Testing

Penetration testing of physical access points can provide information on critical vulnerabilities in the operating environments of organizational systems. Such information can be used to correct weaknesses or deficiencies in physical controls that are necessary to protect organizational systems.

Planned Academy connection

Bare Metal Cyber course coverage for this family.

These titles come from the approved NIST SP 800-53 course plan. They are shown as planned coverage and do not claim a public lesson URL before publication.

  1. Episode 53: Assessment, Authorization, and Monitoring — Part One: Purpose, scope, and outcomes
  2. Episode 54: Assessment, Authorization, and Monitoring — Part Two: Assessment practices and monitoring
  3. Episode 55: Assessment, Authorization, and Monitoring — Part Three: Evidence, POA&M, and pitfalls
  4. Episode 56: Assessment, Authorization, and Monitoring — Part Four: Advanced topics and metrics