Authorization CA-6
Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CA-6 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CA-6 (Authorization) is the formal sign-off to operate. A senior official — the authorizing official (AO) — reviews the system's risk and makes an explicit, accountable decision to accept that risk and let the system run. This is the ‘authorization to operate’ (ATO) that ties the assessment (CA-2) and the plan of action (CA-5) together into a go/no-go decision, and it is re-confirmed on a schedule. It is part of the Low baseline.
What good looks like
- Name an authorizing official — a senior person with the authority to accept risk on the organization's behalf, not the person who built the system.
- Base the decision on evidence — the assessment results (CA-2) and the open items in the plan of action (CA-5).
- Make the acceptance explicit — the authorizing official signs a decision to operate, acknowledging the known residual risk.
- Authorize before operations begin, and cover any common controls the system inherits.
- Re-authorize on a schedule or after a significant change, so the sign-off reflects the system as it is now.
Framework mapping
How to move it toward Implemented
- Write a short authorization decision (the ATO memo): what the system is, its risk posture from the latest assessment, the open plan-of-action items, and the residual risk being accepted.
- Have the authorizing official — someone senior who did not build the system — review and sign it, with a date.
- Set the next re-authorization date (for example, one year out, or on major change), so the sign-off does not silently expire.
- Attach the signed, dated authorization memo as hardening evidence on the asset, naming
CA-6in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.