๐ผ CA-1 Policy and Procedures | | | | |
๐ผ CA-2 Control Assessments | 3 | | | |
๐ผ CA-2(1) Control Assessments _ Independent Assessors | | | | |
๐ผ CA-2(2) Control Assessments _ Specialized Assessments | | | | |
๐ผ CA-2(3) Control Assessments _ Leveraging Results from External Organizations | | | | |
๐ผ CA-3 Information Exchange | 7 | | | |
๐ผ CA-3(1) Information Exchange _ Unclassified National Security System Connections | | | | |
๐ผ CA-3(2) Information Exchange _ Classified National Security System Connections | | | | |
๐ผ CA-3(3) Information Exchange _ Unclassified Non-national Security System Connections | | | | |
๐ผ CA-3(4) Information Exchange _ Connections to Public Networks | | | | |
๐ผ CA-3(5) Information Exchange _ Restrictions on External System Connections | | | | |
๐ผ CA-3(6) Information Exchange _ Transfer Authorizations | | | | |
๐ผ CA-3(7) Information Exchange _ Transitive Information Exchanges | | | | |
๐ผ CA-4 Security Certification | | | | |
๐ผ CA-5 Plan of Action and Milestones | 1 | | | |
๐ผ CA-5(1) Plan of Action and Milestones _ Automation Support for Accuracy and Currency | | | | |
๐ผ CA-6 Authorization | 2 | | | |
๐ผ CA-6(1) Authorization _ Joint Authorization โ Intra-organization | | | | |
๐ผ CA-6(2) Authorization _ Joint Authorization โ Inter-organization | | | | |
๐ผ CA-7 Continuous Monitoring | 6 | | 8 | |
๐ผ CA-7(1) Continuous Monitoring _ Independent Assessment | | | | |
๐ผ CA-7(2) Continuous Monitoring _ Types of Assessments | | | | |
๐ผ CA-7(3) Continuous Monitoring _ Trend Analyses | | | | |
๐ผ CA-7(4) Continuous Monitoring _ Risk Monitoring | | | | |
๐ผ CA-7(5) Continuous Monitoring _ Consistency Analysis | | | | |
๐ผ CA-7(6) Continuous Monitoring _ Automation Support for Monitoring | | | | |
๐ผ CA-8 Penetration Testing | 3 | | | |
๐ผ CA-8(1) Penetration Testing _ Independent Penetration Testing Agent or Team | | | | |
๐ผ CA-8(2) Penetration Testing _ Red Team Exercises | | | | |
๐ผ CA-8(3) Penetration Testing _ Facility Penetration Testing | | | | |
๐ผ CA-9 Internal System Connections | 1 | | | |
๐ผ CA-9(1) Internal System Connections _ Compliance Checks | | | 15 | |