Security Assessment (CA)¶
Domain: Security Assessment (CA)
Requirements in this domain: 4
Assessment Objectives in this domain: 14
CA.L2-3.12.1¶
CA.L2-3.12.1[a]¶
Assessment Objective
the frequency of security control assessments is defined.
Collection Approach: Document
Potential Evidence Examples
SSP or Assessment Policy stating how often security controls are formally assessed (e.g., annually, or per a defined self-assessment cadence).
Assessment Guide – Further Discussion
Are security controls assessed at least annually [a]?
CA.L2-3.12.1[b]¶
Assessment Objective
security controls are assessed with the defined frequency to determine if the controls are effective in their application.
Collection Approach: Artifact
Potential Evidence Examples
Most recent internal or third-party security control assessment report/results, dated within the defined frequency, showing controls were evaluated for effectiveness.
Assessment Guide – Further Discussion
Is the output of the security controls assessment documented [b]?
CA.L2-3.12.2¶
CA.L2-3.12.2[a]¶
Assessment Objective
deficiencies and vulnerabilities to be addressed by the plan of action are identified.
Collection Approach: Artifact
Potential Evidence Examples
Current Plan of Action and Milestones (POA&M) listing each identified deficiency or vulnerability, cross-referenced to the relevant control/practice.
Assessment Guide – Further Discussion
Is there an action plan to remediate identified weaknesses or deficiencies [a]?
CA.L2-3.12.2[b]¶
Assessment Objective
a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities.
Collection Approach: Artifact
Potential Evidence Examples
POA&M entries showing each identified item has a documented corrective action, responsible party, and target completion/milestone date.
Assessment Guide – Further Discussion
Is the action plan maintained as remediation is performed [b]?
CA.L2-3.12.2[c]¶
Assessment Objective
the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.
Collection Approach: Artifact
Potential Evidence Examples
Evidence of POA&M execution — e.g., updated status fields, closure evidence, or a previously closed POA&M item with supporting remediation artifacts (ticket, configuration change, re-scan result).
Assessment Guide – Further Discussion
Does the action plan designate remediation dates and milestones for each item [c]?
CA.L2-3.12.3¶
CA.L2-3.12.3[a]¶
Assessment Objective
security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls.
Collection Approach: Artifact
Potential Evidence Examples
Ongoing continuous-monitoring evidence — e.g., SIEM dashboards/alerts, recurring vulnerability scan reports, periodic internal audit results, or risk assessment updates — demonstrating controls are monitored for continued effectiveness beyond the point-in-time assessment.
Assessment Guide – Further Discussion
- Are the security controls that need to be continuously monitored identified [a]?
- Is the timeframe for continuous monitoring activities to support risk-based decision making defined [a]?
- Is the output of continuous monitoring activities provided to stakeholders [a]?
CA.L2-3.12.4¶
CA.L2-3.12.4[a]¶
Assessment Objective
a system security plan is developed.
Collection Approach: Document
Potential Evidence Examples
Current, signed/approved System Security Plan (SSP) covering the CUI environment.
Assessment Guide – Further Discussion
Do mechanisms exist to develop and periodically update an SSP [a,g]?
CA.L2-3.12.4[b]¶
Assessment Objective
the system boundary is described and documented in the system security plan.
Collection Approach: Document
Potential Evidence Examples
SSP section (with supporting network diagram) that clearly defines the system/authorization boundary — what is in scope and what is explicitly out of scope.
CA.L2-3.12.4[c]¶
Assessment Objective
the system environment of operation is described and documented in the system security plan.
Collection Approach: Document
Potential Evidence Examples
SSP section describing the operating environment — e.g., on-premises, cloud (with provider/service model), hybrid — and relevant environmental characteristics.
CA.L2-3.12.4[d]¶
Assessment Objective
the security requirements identified and approved by the designated authority as non-applicable are identified.
Collection Approach: Document
Potential Evidence Examples
SSP section (or separate memo) documenting any security requirement identified as non-applicable, along with the required DoD CIO (or designated authority) adjudication/approval for that determination.
Assessment Guide – Further Discussion
Are security requirements identified and approved by the designated authority as non-applicable documented [d]?
CA.L2-3.12.4[e]¶
Assessment Objective
the method of security requirement implementation is described and documented in the system security plan.
Collection Approach: Document
Potential Evidence Examples
SSP narrative for each of the 110 security requirements describing how it is implemented (in place, planned, or not applicable), sufficient to show the specific implementation approach rather than a restatement of the requirement text.
CA.L2-3.12.4[f]¶
Assessment Objective
the relationship with or connection to other systems is described and documented in the system security plan.
Collection Approach: Document
Potential Evidence Examples
SSP section (with interconnection diagram or ISA/MOU references) describing relationships/connections to other systems, including external system interconnections.
CA.L2-3.12.4[g]¶
Assessment Objective
the frequency to update the system security plan is defined.
Collection Approach: Document
Potential Evidence Examples
SSP or Configuration/Document Management Policy defining how frequently the SSP must be reviewed and updated (e.g., annually or upon significant change).
Assessment Guide – Further Discussion
Do mechanisms exist to develop and periodically update an SSP [a,g]?
CA.L2-3.12.4[h]¶
Assessment Objective
system security plan is updated with the defined frequency.
Collection Approach: Document
Potential Evidence Examples
Version history/revision log of the SSP (or prior SSP versions) showing it has actually been updated at least as often as the defined frequency.