STIGhub
STIGs
RMF Controls
Compare
← All Controls
CA-1
Assessment, Authorization, and Monitoring
Rev 5
Policy and Procedures
CCI Identifiers (21)
CCI-000238
Defines the frequency to review and update the current assessment, authorization, and monitoring policy.
CCI-000239
Develop and document an organization-level; mission/business process; system-level assessment, authorization, and monitoring policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-000240
Disseminates to organization-defined personnel or roles an organization-level; mission/business process; system-level assessment, authorization, and monitoring policy.
CCI-000241
Review and update the current assessment, authorization, and monitoring policy on an organization-defined frequency.
CCI-000242
Develop and document procedures to facilitate the implementation of the assessment, authorization, and monitoring policy and associated assessment, authorization, and monitoring controls.
CCI-000243
Disseminate to organization-defined personnel or roles procedures to facilitate the implementation of the assessment, authorization, and monitoring policy and associated assessment, authorization, and monitoring controls.
CCI-000244
Review and update the current assessment, authorization, and monitoring procedures on an organization-defined frequency.
CCI-001578
Defines the frequency to review and update the current assessment, authorization, and monitoring procedures.
CCI-002060
The organization develops and documents a security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
deprecated
CCI-002061
Defines the personnel or roles to whom the organization-level; mission/business process; system-level assessment, authorization, and monitoring policy is to be disseminated.
CCI-002062
Defines the personnel or roles to whom the assessment, authorization, monitoring procedures are to be disseminated.
CCI-003849
Disseminate an organization-level; mission/business process; system-level assessment, authorization, and monitoring policy that is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.
CCI-003850
Defines the personnel or roles to whom the assessment, authorization, and monitoring policy is to be disseminated.
CCI-003851
Designate an organization-defined official to manage the development and documentation of the assessment, authorization, and monitoring policy.
CCI-003852
Designate an organization-defined official to manage the development and documentation of the assessment, authorization, and monitoring procedures.
CCI-003853
Designate an organization-defined official to manage the dissemination of the assessment, authorization, and monitoring policy.
CCI-003854
Designate an organization-defined official to manage the dissemination of the assessment, authorization, and monitoring procedures.
CCI-003855
Review and update the current assessment, authorization, and monitoring policy following organization-defined events.
CCI-003856
Defines the events following reviewing and updating the current assessment, authorization, and monitoring policy.
CCI-003857
Review and update the current assessment and authorization procedures following organization-defined events.
CCI-003858
Defines the events following reviewing and updating the current assessment, authorization, and monitoring procedures.
Linked STIG Checks (0)
No STIG checks reference this control.