Skip to main content

πŸ’Ό CA-3 Information Exchange (L)(M)(H)

Description​

a. Approve and manage the exchange of information between the system and other systems using [Selection (one-or-more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service level agreements; user agreements; nondisclosure agreements, [Assignment: organization-defined type of agreement]];

b. Document, as part of each exchange agreement, the interface characteristics, security and privacy requirements, controls, and responsibilities for each system, and the impact level of the information communicated; and

c. Review and update the agreements [FedRAMP Assignment: at least annually and on input from JAB/AO].

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/ca/03
    • /frameworks/fedramp-high-security-controls/ca/03
  • Internal
    • ID: dec-c-89cda8ef

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό CA-3 Information Exchange (L)(M)(H)1
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-3 Information Exchange7

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags