id: "CA-03(07)" title: "Transitive Information Exchanges" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-03.07" priority: "P1" implementation_level: "system" parent: "CA-03" enhancement: True


Identify transitive (downstream) information exchanges with other systems through the systems identified in CA-3a ; and

Take measures to ensure that transitive (downstream) information exchanges cease when the controls on identified transitive (downstream) systems cannot be verified or validated.

Guidance

Transitive or "downstream" information exchanges are information exchanges between the system or systems with which the organizational system exchanges information and other systems. For mission-essential systems, services, and applications, including high value assets, it is necessary to identify such information exchanges. The transparency of the controls or protection measures in place in such downstream systems connected directly or indirectly to organizational systems is essential to understanding the security and privacy risks resulting from those information exchanges. Organizational systems can inherit risk from downstream systems through transitive connections and information exchanges, which can make the organizational systems more susceptible to threats, hazards, and adverse impacts.

Assessment Objective: transitive (downstream) information exchanges with other systems through the systems identified in CA-03a are identified;

Assessment Objective: measures are taken to ensure that transitive (downstream) information exchanges cease when the controls on identified transitive (downstream) systems cannot be verified or validated.

Access control policy

procedures addressing system connections

system and communications protection policy

system interconnection agreements

information exchange security agreements

memoranda of understanding or agreements

service level agreements

non-disclosure agreements

system design documentation

system configuration settings and associated documentation

control assessment report

system audit records

system security plan

privacy plan

other relevant documents or records

Organizational personnel with responsibilities for managing connections to external systems

network administrators

organizational personnel with information security and privacy responsibilities

Mechanisms implementing restrictions on external system connections