PlumbTrackLive demoGRC Risk System

← control library

Authorization CA-6

Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds CA-6 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

CA-6 (Authorization) is the formal sign-off to operate. A senior official — the authorizing official (AO) — reviews the system's risk and makes an explicit, accountable decision to accept that risk and let the system run. This is the ‘authorization to operate’ (ATO) that ties the assessment (CA-2) and the plan of action (CA-5) together into a go/no-go decision, and it is re-confirmed on a schedule. It is part of the Low baseline.

What good looks like

Framework mapping

How to move it toward Implemented