<?xml version="1.0"?>

<rss version="2.0">


<channel>
<title>Home - All Categories - FedRAMP  - Security Assessment and Authorization &amp;#40;CA&amp;#41;  </title>
<link>http://www.compliancewiki.org/category/fedramp/security-assessment-and-authorization-ca/11/</link>
<description>This RSS Feed contains Articles of Category in the knowledge base. You can click on the title to view its content. Powered by PHPKB (https://www.phpkb.com)</description>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-continuous-monitoring-ca-7-635.html</guid>
										<title>FedRAMP - Continuous Monitoring CA-7</title>
										<link>http://www.compliancewiki.org/article/fedramp-continuous-monitoring-ca-7-635.html</link>
										<description><![CDATA[Overview:The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes:a. Establishment of [Assignment: organization-defined metrics] to be monitored;b. Establishment of [Assignment:...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-internal-system-connections-ca-9-639.html</guid>
										<title>FedRAMP - Internal System Connections CA-9</title>
										<link>http://www.compliancewiki.org/article/fedramp-internal-system-connections-ca-9-639.html</link>
										<description><![CDATA[Overview:The organization:a. Authorizes internal connections of [Assignment: organization-defined information system components or classes of components] to the information system; andb. Documents, for each internal connection, the interface...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-security-assessment-and-authorization-policy-and-procedures-ca-1-625.html</guid>
										<title>FedRAMP - Security Assessment and Authorization Policy and Procedures CA-1</title>
										<link>http://www.compliancewiki.org/article/fedramp-security-assessment-and-authorization-policy-and-procedures-ca-1-625.html</link>
										<description><![CDATA[Overview:The organization:a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:1. A security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-independent-assessors-ca-2-1-627.html</guid>
										<title>FedRAMP - Independent Assessors CA-2&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-independent-assessors-ca-2-1-627.html</link>
										<description><![CDATA[Overview:The organization employs assessors or assessment teams with [Assignment: organization-defined level of independence] to conduct security control assessments. Supplemental Guidance:Independent assessors or assessment teams are individuals or...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-independent-penetration-agent-or-team-ca-8-1-638.html</guid>
										<title>FedRAMP - Independent Penetration Agent or Team CA-8&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-independent-penetration-agent-or-team-ca-8-1-638.html</link>
										<description><![CDATA[Overview:The organization employs an independent penetration agent or penetration team to perform penetration testing on the information system or system components. Supplemental Guidance:Independent penetration agents or teams are individuals or...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-plan-of-action-and-milestones-ca-5-633.html</guid>
										<title>FedRAMP - Plan of Action and Milestones CA-5</title>
										<link>http://www.compliancewiki.org/article/fedramp-plan-of-action-and-milestones-ca-5-633.html</link>
										<description><![CDATA[Overview:The organization:a. Develops a plan of action and milestones for the information system to document the organization&rsquo;s planned remedial actions to correct weaknesses or deficiencies noted duringthe assessment of the security controls...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-system-interconnections-ca-3-630.html</guid>
										<title>FedRAMP - System Interconnections CA-3</title>
										<link>http://www.compliancewiki.org/article/fedramp-system-interconnections-ca-3-630.html</link>
										<description><![CDATA[Overview:The organization:a. Authorizes connections from the information system to other information systems through the use of Interconnection Security Agreements;b. Documents, for each interconnection, the interface characteristics, security...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-external-organizations-ca-2-3-629.html</guid>
										<title>FedRAMP - External Organizations CA-2&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-external-organizations-ca-2-3-629.html</link>
										<description><![CDATA[Overview:The organization accepts the results of an assessment of [Assignment: organization-defined information system] performed by [Assignment: organization-defined external organization] when the assessment meets [Assignment: organization-defined...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-security-assessments-ca-2-626.html</guid>
										<title>FedRAMP - Security Assessments CA-2</title>
										<link>http://www.compliancewiki.org/article/fedramp-security-assessments-ca-2-626.html</link>
										<description><![CDATA[Overview:The organization:a. Develops a security assessment plan that describes the scope of the assessment including:1. Security controls and control enhancements under assessment;2. Assessment procedures to be used to determine security control...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-specialized-assessments-ca-2-2-628.html</guid>
										<title>FedRAMP - Specialized Assessments CA-2&#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-specialized-assessments-ca-2-2-628.html</link>
										<description><![CDATA[Overview:The organization includes as part of security control assessments, [Assignment: organization- defined frequency], [Selection: announced; unannounced], [Selection (one or more): in-depth monitoring; vulnerability scanning; malicious user...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-restrictions-on-external-system-connections-ca-3-5-632.html</guid>
										<title>FedRAMP - Restrictions on External System Connections CA-3&#40;5&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-restrictions-on-external-system-connections-ca-3-5-632.html</link>
										<description><![CDATA[Overview:The organization employs [Selection: allow-all, deny-by-exception; deny-all, permit-by-exception] policy for allowing [Assignment: organization-defined information systems] to connect to external information systems. Supplemental Guidance...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-security-authorization-ca-6-634.html</guid>
										<title>FedRAMP - Security Authorization CA-6</title>
										<link>http://www.compliancewiki.org/article/fedramp-security-authorization-ca-6-634.html</link>
										<description><![CDATA[Overview:The organization:a. Assigns a senior-level executive or manager as the authorizing official for the information system;b. Ensures that the authorizing official authorizes the information system for processing before commencing operations;...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-penetration-testing-ca-8-637.html</guid>
										<title>FedRAMP - Penetration Testing CA-8</title>
										<link>http://www.compliancewiki.org/article/fedramp-penetration-testing-ca-8-637.html</link>
										<description><![CDATA[Overview:The organization conducts penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined information systems or system components]. Supplemental Guidance:Penetration testing is a specialized type of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-unclassified-non-national-security-system-connections-ca-3-3-631.html</guid>
										<title>FedRAMP - Unclassified Non-National Security System Connections CA-3&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-unclassified-non-national-security-system-connections-ca-3-3-631.html</link>
										<description><![CDATA[Overview:The organization prohibits the direct connection of an [Assignment: organization-defined unclassified, non-national security system] to an external network without the use of [Assignment; organization-defined boundary protection device]....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-independent-assessment-ca-7-1-636.html</guid>
										<title>FedRAMP - Independent Assessment CA-7&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-independent-assessment-ca-7-1-636.html</link>
										<description><![CDATA[Overview:The organization employs assessors or assessment teams with [Assignment: organization-defined level of independence] to monitor the security controls in the information system on an ongoing basis. Supplemental Guidance:Organizations can...]]></description>

									</item>

</channel>

</rss>