id: "CA-09(01)" title: "Compliance Checks" family: "CA" family_name: "Assessment, Authorization, and Monitoring" sort_id: "ca-09.01" priority: "P1" implementation_level: "system" parent: "CA-09" enhancement: True


Statement

Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.

Guidance

Compliance checks include verification of the relevant baseline configuration.

Assessment Objective: security compliance checks are performed on constituent system components prior to the establishment of the internal connection;

Assessment Objective: privacy compliance checks are performed on constituent system components prior to the establishment of the internal connection.

Assessment, authorization, and monitoring policy

access control policy

procedures addressing system connections

system and communications protection policy

system design documentation

system configuration settings and associated documentation

list of components or classes of components authorized as internal system connections

assessment report

system audit records

system security plan

privacy plan

other relevant documents or records

Organizational personnel with responsibilities for developing, implementing, or authorizing internal system connections

organizational personnel with information security and privacy responsibilities

Mechanisms supporting compliance checks