CA-04 Security Certification
Security Assessment and Authorization
NIST has withdrawn this control from SP 800-53. Its content moved into CA-02. The description below is the one it had before.
Description
The organization conducts an assessment of the security controls in the information system to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
Supplemental Guidance
A security certification is conducted by the organization in support of the OMB Circular A-130, Appendix III requirement for accrediting the information system. The security certification is a key factor in all security accreditation (i.e., authorization) decisions and is integrated into and spans the system development life cycle. The organization assesses all security controls in an information system during the initial security accreditation. Subsequent to the initial accreditation and in accordance with OMB policy, the organization assesses a subset of the controls annually during continuous monitoring (see CA-07). The organization can use the current year’s assessment results obtained during security certification to meet the annual FISMA assessment requirement (see CA-02). NIST Special Publication 800-53A provides guidance on security control assessments. NIST Special Publication 800-37 provides guidance on security certification and accreditation. Related security controls: CA-02, CA-06, SA-11.
Patterns that use this control (7)
Grouped by the emphasis each pattern gives it.