๐ผ CA-1 Policy and Procedures (L)(M)(H) | | | | |
๐ผ CA-2 Control Assessments (L)(M)(H) | 3 | | | |
๐ผ CA-2(1) Independent Assessors (L)(M)(H) | | | | |
๐ผ CA-2(2) Specialized Assessments (H) | | | | |
๐ผ CA-2(3) Leveraging Results from External Organizations (M)(H) | | | | |
๐ผ CA-3 Information Exchange (L)(M)(H) | 1 | | | |
๐ผ CA-3(6) Transfer Authorizations (H) | | | | |
๐ผ CA-5 Plan of Action and Milestones (L)(M)(H) | | | | |
๐ผ CA-6 Authorization (L)(M)(H) | | | | |
๐ผ CA-7 Continuous Monitoring (L)(M)(H) | 2 | | 8 | |
๐ผ CA-7(1) Independent Assessment (M)(H) | | | | |
๐ผ CA-7(4) Risk Monitoring (L)(M)(H) | | | | |
๐ผ CA-8 Penetration Testing (L)(M)(H) | 2 | | | |
๐ผ CA-8(1) Independent Penetration Testing Agent or Team (M)(H) | | | | |
๐ผ CA-8(2) Red Team Exercises (M)(H) | | | | |
๐ผ CA-9 Internal System Connections (L)(M)(H) | | | | |