id: "CA-02(03)" title: "Leveraging Results from External Organizations" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-02.03" priority: "P1" implementation_level: "organization" parent: "CA-02" enhancement: True
Statement
Leverage the results of control assessments performed by {{ insert: param, ca-02.03_odp.01 }} on {{ insert: param, ca-02.03_odp.02 }} when the assessment meets {{ insert: param, ca-02.03_odp.03 }}.
Guidance
Organizations may rely on control assessments of organizational systems by other (external) organizations. Using such assessments and reusing existing assessment evidence can decrease the time and resources required for assessments by limiting the independent assessment activities that organizations need to perform. The factors that organizations consider in determining whether to accept assessment results from external organizations can vary. Such factors include the organization’s past experience with the organization that conducted the assessment, the reputation of the assessment organization, the level of detail of supporting assessment evidence provided, and mandates imposed by applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Accredited testing laboratories that support the Common Criteria Program ISO 15408-1 , the NIST Cryptographic Module Validation Program (CMVP), or the NIST Cryptographic Algorithm Validation Program (CAVP) can provide independent assessment results that organizations can leverage.
Assessment Objective
the results of control assessments performed by {{ insert: param, ca-02.03_odp.01 }} on {{ insert: param, ca-02.03_odp.02 }} are leveraged when the assessment meets {{ insert: param, ca-02.03_odp.03 }}.
Assessment, authorization, and monitoring policy
procedures addressing control assessments
control assessment requirements
control assessment plan
control assessment report
control assessment evidence
plan of action and milestones
system security plan
privacy plan
other relevant documents or records
Organizational personnel with control assessment responsibilities
organizational personnel with information security and privacy responsibilities
personnel performing control assessments for the specified external organization