Skip to content

Security Assessment (CA)

Domain: Security Assessment (CA)
Requirements in this domain: 4
Assessment Objectives in this domain: 14


CA.L2-3.12.1

CA.L2-3.12.1[a]

Assessment Objective

the frequency of security control assessments is defined.

Collection Approach: Document

Potential Evidence Examples

SSP or Assessment Policy stating how often security controls are formally assessed (e.g., annually, or per a defined self-assessment cadence).

Assessment Guide – Further Discussion

Are security controls assessed at least annually [a]?


CA.L2-3.12.1[b]

Assessment Objective

security controls are assessed with the defined frequency to determine if the controls are effective in their application.

Collection Approach: Artifact

Potential Evidence Examples

Most recent internal or third-party security control assessment report/results, dated within the defined frequency, showing controls were evaluated for effectiveness.

Assessment Guide – Further Discussion

Is the output of the security controls assessment documented [b]?


CA.L2-3.12.2

CA.L2-3.12.2[a]

Assessment Objective

deficiencies and vulnerabilities to be addressed by the plan of action are identified.

Collection Approach: Artifact

Potential Evidence Examples

Current Plan of Action and Milestones (POA&M) listing each identified deficiency or vulnerability, cross-referenced to the relevant control/practice.

Assessment Guide – Further Discussion

Is there an action plan to remediate identified weaknesses or deficiencies [a]?


CA.L2-3.12.2[b]

Assessment Objective

a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

Collection Approach: Artifact

Potential Evidence Examples

POA&M entries showing each identified item has a documented corrective action, responsible party, and target completion/milestone date.

Assessment Guide – Further Discussion

Is the action plan maintained as remediation is performed [b]?


CA.L2-3.12.2[c]

Assessment Objective

the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

Collection Approach: Artifact

Potential Evidence Examples

Evidence of POA&M execution — e.g., updated status fields, closure evidence, or a previously closed POA&M item with supporting remediation artifacts (ticket, configuration change, re-scan result).

Assessment Guide – Further Discussion

Does the action plan designate remediation dates and milestones for each item [c]?


CA.L2-3.12.3

CA.L2-3.12.3[a]

Assessment Objective

security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls.

Collection Approach: Artifact

Potential Evidence Examples

Ongoing continuous-monitoring evidence — e.g., SIEM dashboards/alerts, recurring vulnerability scan reports, periodic internal audit results, or risk assessment updates — demonstrating controls are monitored for continued effectiveness beyond the point-in-time assessment.

Assessment Guide – Further Discussion

  • Are the security controls that need to be continuously monitored identified [a]?
  • Is the timeframe for continuous monitoring activities to support risk-based decision making defined [a]?
  • Is the output of continuous monitoring activities provided to stakeholders [a]?

CA.L2-3.12.4

CA.L2-3.12.4[a]

Assessment Objective

a system security plan is developed.

Collection Approach: Document

Potential Evidence Examples

Current, signed/approved System Security Plan (SSP) covering the CUI environment.

Assessment Guide – Further Discussion

Do mechanisms exist to develop and periodically update an SSP [a,g]?


CA.L2-3.12.4[b]

Assessment Objective

the system boundary is described and documented in the system security plan.

Collection Approach: Document

Potential Evidence Examples

SSP section (with supporting network diagram) that clearly defines the system/authorization boundary — what is in scope and what is explicitly out of scope.


CA.L2-3.12.4[c]

Assessment Objective

the system environment of operation is described and documented in the system security plan.

Collection Approach: Document

Potential Evidence Examples

SSP section describing the operating environment — e.g., on-premises, cloud (with provider/service model), hybrid — and relevant environmental characteristics.


CA.L2-3.12.4[d]

Assessment Objective

the security requirements identified and approved by the designated authority as non-applicable are identified.

Collection Approach: Document

Potential Evidence Examples

SSP section (or separate memo) documenting any security requirement identified as non-applicable, along with the required DoD CIO (or designated authority) adjudication/approval for that determination.

Assessment Guide – Further Discussion

Are security requirements identified and approved by the designated authority as non-applicable documented [d]?


CA.L2-3.12.4[e]

Assessment Objective

the method of security requirement implementation is described and documented in the system security plan.

Collection Approach: Document

Potential Evidence Examples

SSP narrative for each of the 110 security requirements describing how it is implemented (in place, planned, or not applicable), sufficient to show the specific implementation approach rather than a restatement of the requirement text.


CA.L2-3.12.4[f]

Assessment Objective

the relationship with or connection to other systems is described and documented in the system security plan.

Collection Approach: Document

Potential Evidence Examples

SSP section (with interconnection diagram or ISA/MOU references) describing relationships/connections to other systems, including external system interconnections.


CA.L2-3.12.4[g]

Assessment Objective

the frequency to update the system security plan is defined.

Collection Approach: Document

Potential Evidence Examples

SSP or Configuration/Document Management Policy defining how frequently the SSP must be reviewed and updated (e.g., annually or upon significant change).

Assessment Guide – Further Discussion

Do mechanisms exist to develop and periodically update an SSP [a,g]?


CA.L2-3.12.4[h]

Assessment Objective

system security plan is updated with the defined frequency.

Collection Approach: Document

Potential Evidence Examples

Version history/revision log of the SSP (or prior SSP versions) showing it has actually been updated at least as often as the defined frequency.