Security Assessment and Authorization (CA) CA-1 Certification, Authorization, Security Assessment Policy and Procedures (H)
The organization:
Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
A security assessment and authorization policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
Procedures to facilitate the implementation of the security assessment and authorization policy and associated security assessment and authorization controls; and
Reviews and updates the current:
Security assessment and authorization policy [FedRAMP Assignment: at least annually]; and
Security assessment and authorization procedures [FedRAMP Assignment: at least at least annually or whenever a significant change occurs].
Share with your friends: |