Policy and Procedures CA-1
Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CA-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CA-1 (Policy and Procedures) is the written foundation for the whole CA (Assessment, Authorization, and Monitoring) family: you develop, publish, and keep current a policy for how the organization assesses, authorizes, and monitors its systems — plus the procedures that carry the policy out. The policy names its purpose, scope, roles, and responsibilities; a designated official owns it; and it is reviewed on a set schedule and after significant events. It sits in the Low baseline and is what every other CA control points back to.
What good looks like
- Write the policy covering purpose, scope, roles, responsibilities, and management commitment — and the procedures that put it into practice.
- Name an owner — a designated official responsible for developing, publishing, and maintaining the policy and procedures.
- Disseminate the policy and procedures to the people and roles who have to follow them, so it is not a document nobody has read.
- Review and update on a defined frequency (for example, yearly) and after significant events — a reorganization, an audit finding, or a major system change.
- Keep it plain and specific to this system — a short, real procedure beats a long template no one uses.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established and communicated
How to move it toward Implemented
- Write a one- to two-page CA policy for this server: its purpose, who it covers, the roles (who assesses, who authorizes, who monitors), and a review cadence — saved as a dated file.
- Add short procedures that point at the real work already happening here — how control assessments run (CA-2), how continuous monitoring works (CA-7), and how findings are tracked (CA-5).
- Name the owner and record the review date, so the next review is scheduled rather than forgotten.
- Attach the dated policy-and-procedures file as hardening evidence on the asset, naming
CA-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.