← Controls / CA

CA-04 Security Certification

Security Assessment and Authorization

Withdrawn

NIST has withdrawn this control from SP 800-53. Its content moved into CA-02. The description below is the one it had before.

Description

The organization conducts an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.

Supplemental Guidance

A security certification is conducted by the organization in support of the OMB Circular A-130, Appendix III requirement for accrediting the information system. The security certification is a key factor in all security accreditation (i.e., authorization) decisions and is integrated into and spans the system development life cycle. The organization assesses all security controls in an information system during the initial security accreditation. Subsequent to the initial accreditation and in accordance with OMB policy, the organization assesses a subset of the controls annually during continuous monitoring (see CA-07). The organization can use the current year’s assessment results obtained during security certification to meet the annual FISMA assessment requirement (see CA-02). NIST Special Publication 800-53A provides guidance on security control assessments. NIST Special Publication 800-37 provides guidance on security certification and accreditation. Related security controls: CA-02, CA-06, SA-11.

Compliance Mappings

ANSSI

Hygiene.31RGS.4.1SecNumCloud.19.2

FINMA Circular 2023/1

IV.D(75)IV.D(76)

OSFI B-13

B-13.1.3B-13.3.5

EU GDPR

Art.32(1)(d)

EU DORA

Art.24(1)Art.25(1)

LGPD + BCB 4893

BCB.Art.10BCB.Art.19

IOSCO Cyber Resilience

TEST-1

CPMI-IOSCO PFMI

CG.TE

ECB CROE

CROE.2.6.1

EBA ICT Guidelines

3.4.6

CMMC 2.0

CA

Common Criteria

CEM

ISAE 3402

Clause 6

FCA SYSC 13

SYSC 13.G.3

ISO 17799 (legacy)

10.3.2

COBIT 4.1 (legacy)

AI7.7