id: "CA-03(07)" title: "Transitive Information Exchanges" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-03.07" priority: "P1" implementation_level: "system" parent: "CA-03" enhancement: True
Identify transitive (downstream) information exchanges with other systems through the systems identified in CA-3a ; and
Take measures to ensure that transitive (downstream) information exchanges cease when the controls on identified transitive (downstream) systems cannot be verified or validated.
Guidance
Transitive or "downstream" information exchanges are information exchanges between the system or systems with which the organizational system exchanges information and other systems. For mission-essential systems, services, and applications, including high value assets, it is necessary to identify such information exchanges. The transparency of the controls or protection measures in place in such downstream systems connected directly or indirectly to organizational systems is essential to understanding the security and privacy risks resulting from those information exchanges. Organizational systems can inherit risk from downstream systems through transitive connections and information exchanges, which can make the organizational systems more susceptible to threats, hazards, and adverse impacts.
Assessment Objective: transitive (downstream) information exchanges with other systems through the systems identified in CA-03a are identified;
Assessment Objective: measures are taken to ensure that transitive (downstream) information exchanges cease when the controls on identified transitive (downstream) systems cannot be verified or validated.
Access control policy
procedures addressing system connections
system and communications protection policy
system interconnection agreements
information exchange security agreements
memoranda of understanding or agreements
service level agreements
non-disclosure agreements
system design documentation
system configuration settings and associated documentation
control assessment report
system audit records
system security plan
privacy plan
other relevant documents or records
Organizational personnel with responsibilities for managing connections to external systems
network administrators
organizational personnel with information security and privacy responsibilities
Mechanisms implementing restrictions on external system connections