id: "CA-03(06)" title: "Transfer Authorizations" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-03.06" priority: "P1" implementation_level: "system" parent: "CA-03" enhancement: True


Statement

Verify that individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or privileges) prior to accepting such data.

Guidance

To prevent unauthorized individuals and systems from making information transfers to protected systems, the protected system verifies—via independent means— whether the individual or system attempting to transfer information is authorized to do so. Verification of the authorization to transfer information also applies to control plane traffic (e.g., routing and DNS) and services (e.g., authenticated SMTP relays).

Assessment Objective

individuals or systems transferring data between interconnecting systems have the requisite authorizations (i.e., write permissions or privileges) prior to accepting such data.

Access control policy

procedures addressing system connections

system and communications protection policy

system interconnection agreements

information exchange security agreements

memoranda of understanding or agreements

service level agreements

non-disclosure agreements

system design documentation

system configuration settings and associated documentation

control assessment report

system audit records

system security plan

privacy plan

other relevant documents or records

Organizational personnel with responsibilities for managing connections to external systems

network administrators

organizational personnel with information security and privacy responsibilities

Mechanisms implementing restrictions on external system connections