← CA-2

Leveraging Results from External Organizations

LOW MODERATE HIGH
1 Overlay 1 Related Control
Graph
Export ▾

Requirements NIST SOURCE

Leverage the results of control assessments performed by [external organization(s)] on [system] when the assessment meets [requirements].

Discussion (NIST Supplemental Guidance)

Organizations may rely on control assessments of organizational systems by other (external) organizations. Using such assessments and reusing existing assessment evidence can decrease the time and resources required for assessments by limiting the independent assessment activities that organizations need to perform. The factors that organizations consider in determining whether to accept assessment results from external organizations can vary. Such factors include the organization’s past experience with the organization that conducted the assessment, the reputation of the assessment organization, the level of detail of supporting assessment evidence provided, and mandates imposed by applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Accredited testing laboratories that support the Common Criteria Program ISO 15408-1 , the NIST Cryptographic Module Validation Program (CMVP), or the NIST Cryptographic Algorithm Validation Program (CAVP) can provide independent assessment results that organizations can leverage.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CA-2(3) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. external organizations from which the results of control assessments are leveraged are defined;
  2. system on which a control assessment was performed by an external organization is defined;
  3. requirements to be met by the control assessment performed by an external organization on the system are defined;
  4. the results of control assessments performed by <CA-02(03)_ODP[01] external organizations> on <CA-02(03)_ODP[02] system> are leveraged when the assessment meets <CA-02(03)_ODP[03] requirements>.

Examine

[SELECT FROM: Assessment, authorization, and monitoring policy; procedures addressing control assessments; control assessment requirements; control assessment plan; control assessment report; control assessment evidence; plan of action and milestones; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with control assessment responsibilities; organizational personnel with information security and privacy responsibilities; personnel performing control assessments for the specified external organization].

Overlays

Showing the OT/ICS overlay for the parent control CA-2 — see the CA-2(3) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CA-2(3). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Assessment, authorization, and monitoring policy
  • control assessment plan
  • plan of action and milestones
  • system security plan
  • privacy plan

Other Records

  • procedures addressing control assessments
  • control assessment requirements
  • control assessment report
  • control assessment evidence
  • other relevant documents or records