PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CA-2 — Control Assessments

Framework: NIST SP 800-53 Rev.5 CA-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Obtain the current security assessment plan and confirm it names the specific controls and control enhancements to be assessed, the assessment procedures for each, the assessment environment, and the assigned assessment team with defined roles.
Examine Review the most recent Security Assessment Report (SAR) and confirm every in-scope control carries an explicit determination (satisfied / other-than-satisfied) supported by referenced evidence rather than an unsupported assertion.
Examine Verify assessor independence and qualifications are documented (per CA-2(1)) and that a conflict-of-interest / impartiality statement exists confirming assessors did not evaluate controls they designed, operate, or manage.
Interview Interview the System Owner or ISSO to confirm control assessments are performed at the organization-defined frequency and prior to each authorization decision, not solely at initial authorization.
Test Select a sample of controls the SAR marks as 'satisfied' and re-perform the corresponding SP 800-53A assessment procedure to confirm the retained evidence actually supports the passing determination.
Examine Trace a sample of 'other-than-satisfied' findings from the SAR into the Plan of Action and Milestones (POA&M) to confirm each weakness was captured with a remediation owner and milestone date.
Examine Confirm completed assessment results are distributed to the designated officials (Authorizing Official and System Owner) and retained as records for the defined retention period.