CA-01 Certification, Accreditation, And Security Assessment Policies And Procedures

Security Assessment and Authorization

Low Moderate High Privacy

Description

The organization develops, disseminates, and periodically reviews/updates: (i) formal, documented, security assessment and certification and accreditation policies that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security assessment and certification and accreditation policies and associated assessment, certification, and accreditation controls.

Supplemental Guidance

The security assessment and certification and accreditation policies and procedures are consistent with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance. The security assessment and certification and accreditation policies can be included as part of the general information security policy for the organization. Security assessment and certification and accreditation procedures can be developed for the security program in general, and for a particular information system, when required. The organization defines what constitutes a significant change to the information system to achieve consistent security reaccreditations. NIST Special Publication 800-53A provides guidance on security control assessments. NIST Special Publication 800-37 provides guidance on security certification and accreditation. NIST Special Publication 800-12 provides guidance on security policies and procedures.

Changes from Rev 4

Title changed from 'Security Assessment and Authorization Policies and Procedures' Requires the selection (one or more) of organization-level; mission/business process-level; system-level assessment, authorization, and monitoring policies Adds text requiring consistency with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines Requires the designation of a specific official to manage the development, documentation, and dissemination of the assessment, authorization, and monitoring policy and procedures New parameters include need to update policy and procedures after specified events in additional to specified frequency Discussion amplifies the need for policy and procedures for risk management, and to help provide security and privacy assurance

Enhancements

(0) None.

Compliance Mappings

ISO 27001:2022

A.5.1

ISO 27002:2022

5.1

COBIT 2019

MEA04

SOC 2 TSC

CC1.2-POF1CC1.4-POF1CC2.2-POF1CC2.2-POF7CC4.1CC5.3CC5.3-POF1CC5.3-POF6CC6.1-POF2CC6.1-POF9CC7.2-POF1P1.1-POF5

PCI DSS v4.0.1

11.112.1

CSA CCM v4

AA-01

CSA AICM v1

A&A-01

ISO 42001:2023

A.5.2

ANSSI

Hygiene.2Hygiene.36RGS.1.3SecNumCloud.19.1SecNumCloud.6.1

FINMA Circular 2023/1

IV.A(23)IV.A(24)IV.D(75)

OSFI B-13

B-13.1.3

EU GDPR

Art.24(1)Art.32(1)(d)Art.32(2)

EU DORA

Art.24(1)Art.5(1)Art.6(1)

BIO2

5.1

RBI CSF

Annex1.18ITGRCA.22ITGRCA.30

FISC Security Guidelines

FISC.O7

LGPD + BCB 4893

BCB.Art.2LGPD.Art.46LGPD.Art.50

HKMA TM-E-1

TME1.2.5

DNB Good Practice

DNB.1.2

SAMA CSF

1.2

NCA ECC

1-31-8

UAE IA

T3

Qatar NIA

GV

CBUAE

CR-14

CBE CSF

GOV-3

SA JS2

JS2-9

CBN CSF

Part6.2

BoG CISD

CISD-COMPCISD-IICISD-ISMSCISD-IV

POPIA

s19

BoM CTRM

1.55.4

IOSCO Cyber Resilience

GOV-1

BCBS 239

Principle 1

CPMI-IOSCO PFMI

PFMI.P2

FFIEC IS

Appendix AII.C.1IV.A

NYDFS 500

500.3

HIPAA Security Rule

§164.308(a)(8)§164.316(a)§164.316(b)(1)

EBA ICT Guidelines

3.2.13.3.13.4.1

BOT Cyber Resilience

Ch1.3Ch6.1

CMMC 2.0

CA

10 CFR 73.54

RG5.71-C-CA

API 1164

Sec 15

IAEA NSS 17-T

Sec 11

CBEST

CBEST.1

ISAE 3402

Clause 1Clause 3

Solvency II

Art.41(1)Art.41(3)DR.258DR.266

Lloyd's Minimum Standards

MS8.2

PRA SS1/23

P2.2P4.1

HITRUST CSF v11

04.a06.c

ISO 27799

18.35.1

NHS DSPT

NDG-5.1

MiCA

Art.34(5)Art.54(1)Art.62(1)Art.62(7)Art.111(1)

Basel SCO60

SCO60.3SCO60.50SCO60.60SCO60.74

BSSC Standards

NOS-01TIS-01KMS-01GSP-10

SEC Custody (Digital Assets)

SEC-CD-01SEC-CD-14SEC-CD-17SEC-CD-19

ISO 17799 (legacy)

6.1.410.3.215.1.1

COBIT 4.1 (legacy)

PO10.12PC5