# CA-04 Security Certification

NIST SP 800-53 control. Family: CA Security Assessment and Authorization. Function: detective. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into CA-02.

Statement: The organization conducts an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
Guidance: A security certification is conducted by the organization in support of the OMB Circular A-130, Appendix III requirement for accrediting the information system. The security certification is a key factor in all security accreditation (i.e., authorization) decisions and is integrated into and spans the system development life cycle. The organization assesses all security controls in an information system during the initial security accreditation. Subsequent to the initial accreditation and in accordance with OMB policy, the organization assesses a subset of the controls annually during continuous monitoring (see CA-07). The organization can use the current year’s assessment results obtained during security certification to meet the annual FISMA assessment requirement (see CA-02). NIST Special Publication 800-53A provides guidance on security control assessments. NIST Special Publication 800-37 provides guidance on security certification and accreditation. Related security controls: CA-02, CA-06, SA-11.

## Patterns that use it (7)
- Critical (1): SP-004 SOA Publication and Location Pattern
- Important (1): SP-018 Information Security Management System
- Standard (5): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-016 DMZ Module

## Clauses by framework (14 frameworks)
- anssi: Hygiene.31, RGS.4.1, SecNumCloud.19.2
- osfi_b13: B-13.1.3, B-13.3.5
- finma_circular: IV.D(75), IV.D(76)
- gdpr: Art.32(1)(d)
- dora: Art.24(1), Art.25(1)
- lgpd_bcb: BCB.Art.10, BCB.Art.19
- cpmi_pfmi: CG.TE
- eba_ict: 3.4.6
- ecb_croe: CROE.2.6.1
- iosco_cyber: TEST-1
- cmmc_2: CA
- common_criteria: CEM
- isae_3402: Clause 6
- fca_sysc_13: SYSC 13.G.3

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CA-04
- Clauses only: /api/v1/controls/CA-04?fields=mappings
- Page for people: /controls/ca-04/
