id: "CA-09(01)" title: "Compliance Checks" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-09.01" priority: "P1" implementation_level: "system" parent: "CA-09" enhancement: True
Statement
Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
Guidance
Compliance checks include verification of the relevant baseline configuration.
Assessment Objective: security compliance checks are performed on constituent system components prior to the establishment of the internal connection;
Assessment Objective: privacy compliance checks are performed on constituent system components prior to the establishment of the internal connection.
Assessment, authorization, and monitoring policy
access control policy
procedures addressing system connections
system and communications protection policy
system design documentation
system configuration settings and associated documentation
list of components or classes of components authorized as internal system connections
assessment report
system audit records
system security plan
privacy plan
other relevant documents or records
Organizational personnel with responsibilities for developing, implementing, or authorizing internal system connections
organizational personnel with information security and privacy responsibilities
Mechanisms supporting compliance checks