# CA-02 Control Assessments

NIST SP 800-53 control. Family: CA Security Assessment and Authorization. Function: detective. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Select the appropriate assessor or assessment team for the type of assessment to be conducted; b. Develop a control assessment plan that describes the scope of the assessment including: 1. Controls and control enhancements under assessment; 2. Assessment procedures to be used to determine control effectiveness; and 3. Assessment environment, assessment team, and assessment roles and responsibilities; c. Ensure the control assessment plan is reviewed and approved by the authorizing official or designated representative prior to conducting the assessment; d. Assess the controls in the system and its environment of operation [Assignment: organization-defined frequency] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security and privacy requirements; e. Produce a control assessment report that document the results of the assessment; and f. Provide the results of the control assessment to [Assignment: organization-defined individuals or roles].
Guidance: Organizations ensure that control assessors possess the required skills and technical expertise to develop effective assessment plans and to conduct assessments of system-specific, hybrid, common, and program management controls, as appropriate. The required skills include general knowledge of risk management concepts and approaches as well as comprehensive knowledge of and experience with the hardware, software, and firmware system components implemented. Organizations assess controls in systems and the environments in which those systems operate as part of initial and ongoing authorizations, continuous monitoring, FISMA annual assessments, system design and development, systems security engineering, privacy engineering, and the system development life cycle. Assessments help to ensure that organizations meet information security and privacy requirements, identify weaknesses and deficiencies in the system design and development process, provide essential information needed to make risk-based decisions as part of authorization processes, and comply with vulnerability mitigation procedures. Organizations conduct assessments on the implemented controls as documented in security and privacy plans. Assessments can also be conducted throughout the system development life cycle as part of systems engineering and systems security engineering processes. The design for controls can be assessed as RFPs are developed, responses assessed, and design reviews conducted. If a design to implement controls and subsequent implementation in accordance with the design are assessed during development, the final control testing can be a simple confirmation utilizing previously completed control assessment and aggregating the outcomes. Organizations may develop a single, consolidated security and privacy assessment plan for the system or maintain separate plans. A consolidated assessment plan clearly delineates the roles and responsibilities for control assessment. If multiple organizations participate in assessing a system, a coordinated approach can reduce redundancies and associated costs. Organizations can use other types of assessment activities, such as vulnerability scanning and system monitoring, to maintain the security and privacy posture of systems during the system life cycle. Assessment reports document assessment results in sufficient detail, as deemed necessary by organizations, to determine the accuracy and completeness of the reports and whether the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting requirements. Assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted. For example, assessments conducted in support of authorization decisions are provided to authorizing officials, senior agency officials for privacy, senior agency information security officers, and authorizing official designated representatives. To satisfy annual assessment requirements, organizations can use assessment results from the following sources: initial or ongoing system authorizations, continuous monitoring, systems engineering processes, or system development life cycle activities. Organizations ensure that assessment results are current, relevant to the determination of control effectiveness, and obtained with the appropriate level of assessor independence. Existing control assessment results can be reused to the extent that the results are still valid and can also be supplemented with additional assessments as needed. After the initial authorizations, organizations assess controls during continuous monitoring. Organizations also establish the frequency for ongoing assessments in accordance with organizational continuous monitoring strategies. External audits, including audits by external entities such as regulatory agencies, are outside of the scope of CA-02.

## Enhancements (3)
- CA-02(01) Independent Assessors. Baselines: moderate, high
- CA-02(02) Specialized Assessments. Baselines: high
- CA-02(03) Leveraging Results from External Organizations
Each enhancement's statement: /api/v1/controls/CA-02?fields=enhancements

## Patterns that use it (28)
- Critical (4): SP-018 Information Security Management System; SP-035 Offensive Security Testing; SP-043 Security Metrics and Measurement; SP-044 SaaS Identity Lifecycle Management
- Important (19): SP-006 Wireless- Private Network Pattern; SP-007 Wireless- Public Hotspot Pattern; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-012 Secure Software Development Lifecycle; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-026 PCI Full Environment; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-033 Passkey Authentication; SP-034 Cyber Resilience; SP-036 Incident Response; SP-037 Privileged User Management; SP-038 Vulnerability Management and Patching; SP-042 Third Party Risk Management; SP-045 AI Governance and Responsible AI; SP-046 External Attack Surface Management
- Standard (5): SP-001 Client Module; SP-002 Server Module; SP-021 Realtime Collaboration Pattern; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection

## Clauses by framework (75 frameworks)
- iso_27001_2022: 8.1, 9.2, A.5.30, A.5.35, A.5.36, A.8.29, A.8.34. OSA's own, not in NIST's crosswalk: 8.1, A.5.35, A.8.34
- iso_27002_2022: 5.35, 5.36, 8.29, 8.34
- cobit_2019: APO11, APO13, BAI07, MEA02, MEA03, MEA04
- pci_dss_v4: 12.4, 12.5
- nist_csf_2: GV.OV-02, GV.OV-03, ID.IM-01, ID.IM-02, ID.IM-03, ID.RA-01. OSA's own, not in NIST's crosswalk: GV.OV-02, GV.OV-03
- cis_controls_v8: CIS 15.5, CIS 18.4
- soc2_tsc: CC1.1-POF3, CC3.1, CC4.1, CC5.2, CC6.1-POF2
- iso_42001_2023: A.5.2, A.5.3, A.6.2.4
- nis2: Art. 21(2)(f), Art. 24, Art. 32
- apra_cps_234: Para 22-23, Para 24, Para 27-28
- mas_trm: 13
- pra_op_resilience: SS1/21-7.1, SS2/21-6.2
- bsi_grundschutz: ORP.5
- anssi: Hygiene.3, Hygiene.31, Hygiene.41, RGS.4.1, SecNumCloud.19.2
- osfi_b13: B-13.1.3, B-13.3.5
- finma_circular: IV.D(75), IV.D(76), IV.D(77)
- gdpr: Art.32(1)(d), Art.35(1), Art.35(7)
- dora: Art.6(4), Art.24(1), Art.24(2), Art.25(1)
- bio2: 5.35, 5.36, 8.29, 8.34
- rbi_csf: Annex1.18, ITGRCA.26, ITGRCA.30
- fisc: FISC.O7
- lgpd_bcb: BCB.Art.10, BCB.Art.18, BCB.Art.19, LGPD.Art.37-38, LGPD.Art.50
- hkma_tme1: TME1.2.6, TME1.3.3, TME1.7.4
- mlps_2: 8.1.7.2, 8.1.9.5, 8.1.9.6
- dnb_good_practice: DNB.10.4, DNB.16.1, DNB.16.2, DNB.16.3, DNB.16.4, DNB.16.5, DNB.22.1
- cra: CRA.I.2a, CRA.II.3
- cbb_tm: TM-16
- cbuae: CR-10, CR-14
- nca_ecc: 1-7, 1-8
- qatar_nia: GV, OS, RM, SD
- sama_csf: 1.3, 1.9, 2.2, 4.2
- bog_cisd: CISD-COMP, CISD-ISMS, CISD-IV
- bom_ctrm: 1.5, 3.1, 4.3, 5.4
- cbe_csf: GOV-3, OVM-3
- cbn_csf: Part2.3, Part5.1, Part6.2, Part7.2
- popia: s19
- sa_js2: JS2-6.2, JS2-7.7, JS2-9
- bcbs_239: Principle 7, Principle 8, Principle 12
- bot_cyber: Ch1.3, Ch3.2, Ch6.1
- cpmi_pfmi: CG.LE, CG.TE, PFMI.P3, PFMI.P17
- eba_ict: 3.3.6, 3.4.6
- ecb_croe: CROE.2.2.1, CROE.2.6.1, CROE.2.8.1
- ffiec_is: Appendix A, II.A, II.A.2, II.B, II.C.3, II.C.4, II.D, IV.A, IV.A.1, IV.A.2, IV.A.3, IV.A.4
- hipaa_sr: §164.308(a)(1)(i), §164.308(a)(1)(ii)(A), §164.308(a)(7)(ii)(D), §164.308(a)(8)
- iosco_cyber: LE-2, SA-3, TEST-1, TEST-3, TEST-4
- nydfs_500: 500.2, 500.9
- sebi_cscrf: AUDIT, CCI, CERTIF, DE.VA, GV.OV, RC.IM, RS.IM, VAPT
- cmmc_2: CA, RA
- nrc_73_54: RG5.71-C-CA, RG5.71-C-PL
- tsa_psd: SD-1 Sec 3, SD-2 Sec G
- api_1164: Sec 15
- iaea_nss: Sec 11
- cbest: CBEST.7, CBEST.10
- tiber_eu: TIBER.CLOSE, TIBER.REM
- pci_hsm: 10
- common_criteria: CC Part 3 — SAR, CEM
- isae_3402: Clause 2, Clause 3, Clause 5, Clause 6, Clause 10
- fca_sysc_13: SYSC 13.5.3, SYSC 13.G.3
- fda_21_cfr_11: §11.10(a), §11.300(e)
- fda_cyber: 524B-4, SPDF-2
- hitrust_csf: 00.b, 04.b, 06.c, 12.c
- iso_27799: 18.3, 18.4
- lloyds_ms: MS10.2
- naic_ds: 4, 4-monitoring, 4A, 4E, 7
- nhs_dspt: NDG-5.1, NDG-7.3
- pra_ss1_23: P2.2, P4.1, P4.2
- solvency_ii: Art.45, Art.46, Art.47, DR.266, EIOPA-Cloud-GL7, EIOPA-ICT-4.2
- csa_ccm_v4: AA-01, AA-02, AA-03, AA-04, AA-05, AA-06, CEK-09, GRC-07, STA-05, STA-06, STA-11, STA-12, STA-13
- csa_aicm: A&A-01, A&A-02, A&A-03, A&A-04, A&A-05, A&A-06, CEK-09, GRC-07, GRC-12, STA-05, STA-06, STA-11, STA-12, STA-13
- ccss_v9: 1.01.6, 2.01.1, 2.01.2, 2.01.3, 2.02.3, 2.03.1, 2.03.2
- mica: Art.34(5), Art.43(1), Art.94(1), Art.111(1)
- basel_sco60: SCO60.5, SCO60.14, SCO60.21, SCO60.41, SCO60.51, SCO60.52, SCO60.64, SCO60.65, SCO60.74, SCO60.85
- bssc: GSP-10, GSP-15, TIS-02, TIS-06
- sec_custody_digital: SEC-CD-01, SEC-CD-10, SEC-CD-13, SEC-CD-14, SEC-CD-17
- dpdpa: Act.8(4), Act.10(2)(b), Act.10(2)(c), Rules.6(1)(g), Rules.13(1)-(2), Rules.Sch1.A.9, Rules.Sch1.B.12
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CA-02
- Clauses only: /api/v1/controls/CA-02?fields=mappings
- Page for people: /controls/ca-02/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
