πΌ CA-2 SECURITY ASSESSMENTS
- Contextual name: πΌ CA-2 SECURITY ASSESSMENTS
- ID:
/frameworks/nist-sp-800-53-r4/ca/02
- Located in: πΌ CA SECURITY ASSESSMENT AND AUTHORIZATION
Descriptionβ
The organization: CA-2a. Develops a security assessment plan that describes the scope of the assessment including: CA-2a.1. Security controls and control enhancements under assessment; CA-2a.2. Assessment procedures to be used to determine security control effectiveness; and CA-2a.3. Assessment environment, assessment team, and assessment roles and responsibilities; CA-2b. Assesses the security controls in the information system and its environment of operation [Assignment: organization-defined frequency] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements; CA-2c. Produces a security assessment report that documents the results of the assessment; and CA-2d. Provides the results of the security control assessment to [Assignment: organization-defined individuals or roles].
Similarβ
- Internal
- ID:
dec-c-3073ee37
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability | ||||
πΌ NIST CSF v1.1 β πΌ DE.DP-2: Detection activities comply with all applicable requirements | 7 | 7 | ||
πΌ NIST CSF v1.1 β πΌ DE.DP-3: Detection processes are tested | 14 | 14 | ||
πΌ NIST CSF v1.1 β πΌ DE.DP-4: Event detection information is communicated | 30 | 33 | ||
πΌ NIST CSF v1.1 β πΌ DE.DP-5: Detection processes are continuously improved | 14 | 16 | ||
πΌ NIST CSF v1.1 β πΌ ID.RA-1: Asset vulnerabilities are identified and documented | 14 | 15 | ||
πΌ NIST CSF v1.1 β πΌ PR.IP-7: Protection processes are improved | 2 | |||
πΌ NIST CSF v1.1 β πΌ RS.CO-3: Information is shared consistent with response plans | 16 | 17 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CA-2 (1) INDEPENDENT ASSESSORS | ||||
πΌ CA-2 (2) SPECIALIZED ASSESSMENTS | ||||
πΌ CA-2 (3) EXTERNAL ORGANIZATIONS |