πΌ CA-1 Policy and Procedures
- Contextual name: πΌ CA-1 Policy and Procedures
- ID:
/frameworks/nist-sp-800-53-r5/ca/01
- Located in: πΌ CA Assessment, Authorization, And Monitoring
Descriptionβ
a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
- [Selection (one or more): Organization-level; Mission/business process-level; System-level] assessment, authorization, and monitoring policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
- Procedures to facilitate the implementation of the assessment, authorization, and monitoring policy and the associated assessment, authorization, and monitoring controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the assessment, authorization, and monitoring policy and procedures; and c. Review and update the current assessment, authorization, and monitoring:
- Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and
- Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
Similarβ
- Internal
- ID:
dec-c-408ca7b6
- ID:
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|