Control Assessments CA-2
Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CA-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CA-2 (Control Assessments) is the checkup: you assess the security and privacy controls to confirm each one is implemented correctly and actually working. It uses a written assessment plan, produces an assessment report, and shares the results with leadership. At Moderate, enhancement CA-2(1) adds an independent assessor.
What good looks like
- Develop an assessment plan — the controls in scope, the procedures, and the expected outcome for each.
- Assess whether each control is implemented correctly and producing the intended result.
- Capture the results in an assessment report.
- Share results with the officials responsible for the system.
- At Moderate, use an independent assessor who did not build the control (CA-2(1)).
Framework mapping
- NIST CSF 2.0 — ID.IM-02 — Improvements are identified from security tests and assessments
How to move it toward Implemented
- An assessment was performed: Lynis produced a hardening index of 68, and each guard was proven by a negative-control test —
nmaptrips a SCAN alert, brute force trips a ban, and an AIDE (Advanced Intrusion Detection Environment) canary file is caught — with the as-built and Lynis report captured. - Two things are missing for Moderate: a documented assessment plan (scope, the controls in scope, and the procedures and tests used) and an independent assessor — the person assessing should not be the person who built the control (CA-2(1)).
- Write the assessment plan, have someone other than the builder run and sign the results, and attach both the plan and the signed report as asset-scoped evidence naming CA-2 to move from partial toward Completed.