CA-02 Security Assessments

Security Assessment and Authorization

Low Moderate High Privacy

Description

The organization conducts an assessment of the security controls in the information system [Assignment: organization-defined frequency, at least annually] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.\n

Supplemental Guidance

This control is intended to support the FISMA requirement that the management, operational, and technical controls in each information system contained in the inventory of major information systems be assessed with a frequency depending on risk, but no less than annually. The FISMA requirement for (at least) annual security control assessments should not be interpreted by organizations as adding additional assessment requirements to those requirements already in place in the security certification and accreditation process. To satisfy the annual FISMA assessment requirement, organizations can draw upon the security control assessment results from any of the following sources, including but not limited to: (i) security certifications conducted as part of an information system accreditation or reaccreditation process (see CA-4); (ii) continuous monitoring activities (see CA-7); or (iii) testing and evaluation of the information system as part of the ongoing system development life cycle process (provided that the testing and evaluation results are current and relevant to the determination of security control effectiveness). Existing security assessment results are reused to the extent that they are still valid and are supplemented with additional assessments as needed. Reuse of assessment information is critical in achieving a broad-based, cost-effective, and fully integrated security program capable of producing the needed evidence to determine the actual security status of the information system. OMB does not require an annual assessment of all security controls employed in an organizational information system. In accordance with OMB policy, organizations must annually assess a subset of the security controls based on: (i) the FIPS 199 security categorization of the information system; (ii) the specific security controls selected and employed by the organization to protect the information system; and (iii) the level of assurance (or confidence) that the organization must have in determining the effectiveness of the security controls in the information system. It is expected that the organization will assess all of the security controls in the information system during the three-year accreditation cycle. The organization can use the current year’s assessment results obtained during security certification to meet the annual FISMA assessment requirement (see CA- 4). NIST Special Publication 800-53A provides guidance on security control assessments to include reuse of existing assessment results. Related security controls: CA-4, CA-6, CA-7, SA- 11.\n

Changes from Rev 4

Title changed from 'Security Assessments' Control text is more generic and drops security emphasis Discussion includes need to ensure control assessors possess required skills and technical expertise and results reviewed and approved by the authorizing official or designee Addresses withdrawn App J control AR-4

Enhancements

(0) None.\n

Compliance Mappings

ISO 27001:2022

8.19.19.1(a)9.1(b)9.1(c)9.1(d)9.1(e)9.1(f)

ISO 27002:2022

5.215.235.355.365.88.298.348.8

COBIT 2019

BAI01.01BAI01.02BAI01.03BAI01.04BAI01.05BAI01.06BAI01.07BAI01.08BAI01.09BAI02.01BAI02.02BAI02.03BAI02.04BAI03.01BAI03.02BAI03.03BAI03.04BAI03.05BAI03.06BAI03.07BAI03.08BAI03.09BAI03.10BAI03.11BAI03.12BAI04.01BAI04.02BAI04.03BAI04.04BAI04.05BAI11.01BAI11.02BAI11.03BAI11.04BAI11.05BAI11.06BAI11.07BAI11.08BAI11.09EDM03.01MEA02.01MEA02.02MEA02.03MEA02.04

NIST CSF 2.0

ID.IM-01ID.IM-02ID.RA-01

SOC 2 TSC

CC1.1-POF3CC3.1CC4.1CC4.1-POF8CC5.2CC6.1-POF2CC7.2-POF4

ISO 17799 (legacy)

6.1.815.2.115.2.2

COBIT 4.1 (legacy)

DS5.5