← Controls / CA

CA-02 Control Assessments

Security Assessment and Authorization

Low Moderate High Privacy

Description

a. Select the appropriate assessor or assessment team for the type of assessment to be conducted; b. Develop a control assessment plan that describes the scope of the assessment including: 1. Controls and control enhancements under assessment; 2. Assessment procedures to be used to determine control effectiveness; and 3. Assessment environment, assessment team, and assessment roles and responsibilities; c. Ensure the control assessment plan is reviewed and approved by the authorizing official or designated representative prior to conducting the assessment; d. Assess the controls in the system and its environment of operation [Assignment: organization-defined frequency] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security and privacy requirements; e. Produce a control assessment report that document the results of the assessment; and f. Provide the results of the control assessment to [Assignment: organization-defined individuals or roles].

Supplemental Guidance

Organizations ensure that control assessors possess the required skills and technical expertise to develop effective assessment plans and to conduct assessments of system-specific, hybrid, common, and program management controls, as appropriate. The required skills include general knowledge of risk management concepts and approaches as well as comprehensive knowledge of and experience with the hardware, software, and firmware system components implemented. Organizations assess controls in systems and the environments in which those systems operate as part of initial and ongoing authorizations, continuous monitoring, FISMA annual assessments, system design and development, systems security engineering, privacy engineering, and the system development life cycle. Assessments help to ensure that organizations meet information security and privacy requirements, identify weaknesses and deficiencies in the system design and development process, provide essential information needed to make risk-based decisions as part of authorization processes, and comply with vulnerability mitigation procedures. Organizations conduct assessments on the implemented controls as documented in security and privacy plans. Assessments can also be conducted throughout the system development life cycle as part of systems engineering and systems security engineering processes. The design for controls can be assessed as RFPs are developed, responses assessed, and design reviews conducted. If a design to implement controls and subsequent implementation in accordance with the design are assessed during development, the final control testing can be a simple confirmation utilizing previously completed control assessment and aggregating the outcomes. Organizations may develop a single, consolidated security and privacy assessment plan for the system or maintain separate plans. A consolidated assessment plan clearly delineates the roles and responsibilities for control assessment. If multiple organizations participate in assessing a system, a coordinated approach can reduce redundancies and associated costs. Organizations can use other types of assessment activities, such as vulnerability scanning and system monitoring, to maintain the security and privacy posture of systems during the system life cycle. Assessment reports document assessment results in sufficient detail, as deemed necessary by organizations, to determine the accuracy and completeness of the reports and whether the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting requirements. Assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted. For example, assessments conducted in support of authorization decisions are provided to authorizing officials, senior agency officials for privacy, senior agency information security officers, and authorizing official designated representatives. To satisfy annual assessment requirements, organizations can use assessment results from the following sources: initial or ongoing system authorizations, continuous monitoring, systems engineering processes, or system development life cycle activities. Organizations ensure that assessment results are current, relevant to the determination of control effectiveness, and obtained with the appropriate level of assessor independence. Existing control assessment results can be reused to the extent that the results are still valid and can also be supplemented with additional assessments as needed. After the initial authorizations, organizations assess controls during continuous monitoring. Organizations also establish the frequency for ongoing assessments in accordance with organizational continuous monitoring strategies. External audits, including audits by external entities such as regulatory agencies, are outside of the scope of CA-02.

Changes from Rev 4

Title changed from 'Security Assessments' Control text is more generic and drops security emphasis Discussion includes need to ensure control assessors possess required skills and technical expertise and results reviewed and approved by the authorizing official or designee Addresses withdrawn App J control AR-04

Enhancements (3)

What NIST adds to this control. Select one to read its statement.

CA-02(01) Independent Assessors ModerateHigh

Employ independent assessors or assessment teams to conduct control assessments.

CA-02(02) Specialized Assessments High

Include as part of control assessments, [Assignment: organization-defined frequency], [Selection (one): announced; unannounced], [Selection (one or more): in-depth monitoring; security instrumentation; automated security test cases; vulnerability scanning; malicious user testing; insider threat assessment; performance and load testing; data leakage or data loss assessment; [Assignment: organization-defined other forms of assessment]].

CA-02(03) Leveraging Results from External Organizations

Leverage the results of control assessments performed by [Assignment: organization-defined external organization(s)] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements].

Compliance Mappings

ISO 27001:2022

8.19.2A.5.30A.5.35A.5.36A.8.29A.8.34

ISO 27002:2022

5.355.368.298.34

COBIT 2019

APO11APO13BAI07MEA02MEA03MEA04

CIS Controls v8

CIS 15.5CIS 18.4

NIST CSF 2.0

GV.OV-02GV.OV-03ID.IM-01ID.IM-02ID.IM-03ID.RA-01

SOC 2 TSC

CC1.1-POF3CC3.1CC4.1CC5.2CC6.1-POF2

PCI DSS v4.0.1

12.412.5

CSA CCM v4

AA-01AA-02AA-03AA-04AA-05AA-06CEK-09GRC-07STA-05STA-06STA-11STA-12STA-13

CSA AICM v1

A&A-01A&A-02A&A-03A&A-04A&A-05A&A-06CEK-09GRC-07GRC-12STA-05STA-06STA-11STA-12STA-13

ISO 42001:2023

A.5.2A.5.3A.6.2.4

NIS2 Directive

Art. 21(2)(f)Art. 24Art. 32

PRA Operational Resilience

SS1/21-7.1SS2/21-6.2

MAS TRM

13

APRA CPS 234

Para 22-23Para 24Para 27-28

BSI IT-Grundschutz

ORP.5

ANSSI

Hygiene.3Hygiene.31Hygiene.41RGS.4.1SecNumCloud.19.2

FINMA Circular 2023/1

IV.D(75)IV.D(76)IV.D(77)

OSFI B-13

B-13.1.3B-13.3.5

EU GDPR

Art.32(1)(d)Art.35(1)Art.35(7)

EU DORA

Art.6(4)Art.24(1)Art.24(2)Art.25(1)

BIO2

5.355.368.298.34

RBI CSF

Annex1.18ITGRCA.26ITGRCA.30

FISC Security Guidelines

FISC.O7

LGPD + BCB 4893

BCB.Art.10BCB.Art.18BCB.Art.19LGPD.Art.37-38LGPD.Art.50

HKMA TM-E-1

TME1.2.6TME1.3.3TME1.7.4

MLPS 2.0

8.1.7.28.1.9.58.1.9.6

DNB Good Practice

DNB.10.4DNB.16.1DNB.16.2DNB.16.3DNB.16.4DNB.16.5DNB.22.1

EU CRA

CRA.I.2aCRA.II.3

SAMA CSF

1.31.92.24.2

NCA ECC

1-71-8

CBB TM

TM-16

Qatar NIA

GVOSRMSD

CBUAE

CR-10CR-14

CBE CSF

GOV-3OVM-3

SA JS2

JS2-6.2JS2-7.7JS2-9

CBN CSF

Part2.3Part5.1Part6.2Part7.2

BoG CISD

CISD-COMPCISD-ISMSCISD-IV

POPIA

s19

BoM CTRM

1.53.14.35.4

IOSCO Cyber Resilience

LE-2SA-3TEST-1TEST-3TEST-4

BCBS 239

Principle 7Principle 8Principle 12

CPMI-IOSCO PFMI

CG.LECG.TEPFMI.P3PFMI.P17

FFIEC IS

Appendix AII.AII.A.2II.BII.C.3II.C.4II.DIV.AIV.A.1IV.A.2IV.A.3IV.A.4

NYDFS 500

500.2500.9

HIPAA Security Rule

§164.308(a)(1)(i)§164.308(a)(1)(ii)(A)§164.308(a)(7)(ii)(D)§164.308(a)(8)

ECB CROE

CROE.2.2.1CROE.2.6.1CROE.2.8.1

EBA ICT Guidelines

3.3.63.4.6

SEBI CSCRF

AUDITCCICERTIFDE.VAGV.OVRC.IMRS.IMVAPT

BOT Cyber Resilience

Ch1.3Ch3.2Ch6.1

CMMC 2.0

CARA

10 CFR 73.54

RG5.71-C-CARG5.71-C-PL

TSA Pipeline SD

SD-1 Sec 3SD-2 Sec G

API 1164

Sec 15

IAEA NSS 17-T

Sec 11

CBEST

CBEST.7CBEST.10

TIBER-EU

TIBER.CLOSETIBER.REM

PCI HSM

10

Common Criteria

CC Part 3 — SARCEM

ISAE 3402

Clause 2Clause 3Clause 5Clause 6Clause 10

Solvency II

Art.45Art.46Art.47DR.266EIOPA-Cloud-GL7EIOPA-ICT-4.2

Lloyd's Minimum Standards

MS10.2

NAIC Insurance Data Security

44-monitoring4A4E7

PRA SS1/23

P2.2P4.1P4.2

FCA SYSC 13

SYSC 13.5.3SYSC 13.G.3

HITRUST CSF v11

00.b04.b06.c12.c

FDA 21 CFR Part 11

§11.10(a)§11.300(e)

FDA Cybersecurity Guidance

524B-4SPDF-2

ISO 27799

18.318.4

NHS DSPT

NDG-5.1NDG-7.3

CCSS v9.0

1.01.62.01.12.01.22.01.32.02.32.03.12.03.2

MiCA

Art.34(5)Art.43(1)Art.94(1)Art.111(1)

Basel SCO60

SCO60.5SCO60.14SCO60.21SCO60.41SCO60.51SCO60.52SCO60.64SCO60.65SCO60.74SCO60.85

BSSC Standards

GSP-10GSP-15TIS-02TIS-06

SEC Custody (Digital Assets)

SEC-CD-01SEC-CD-10SEC-CD-13SEC-CD-14SEC-CD-17

India DPDPA

Act.8(4)Act.10(2)(b)Act.10(2)(c)Rules.6(1)(g)Rules.13(1)-(2)Rules.Sch1.A.9Rules.Sch1.B.12

ISO 17799 (legacy)

6.1.815.2.115.2.2

COBIT 4.1 (legacy)

DS5.5