|
controlCA-3
Information Exchange (CA-3)
Approve and manage the exchange of information between the system and other systems using [organization-defined]; Document, as part of each exchange agreement, the interface characteristics, security and privacy requirements, controls, and responsibilities for each system, and the impact level of the information communicated; and Review and update the agreements [organization-defined].
Security Baselines
LOWMODERATEHIGH
assessmentauthorizationmonitoring
Why These Connect
Maps To10
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports17
These related controls work together — a change to one may affect the others.
Enhances7
These enhancements add specific capabilities or refinements to the base control.
Related Controls(13)
AC-4Information Flow Enforcement (AC-4)
MH
AC-17Remote Access (AC-17)LMH
AC-20Use of External Systems (AC-20)LMH
AU-16Cross-organizational Audit Logging (AU-16)CA-6Authorization (CA-6)LMH
IA-3Device Identification and Authentication (IA-3)MH
IR-4Incident Handling (IR-4)LMH
PL-2System Security and Privacy Plans (PL-2)LMH
PT-7Specific Categories of Personally Identifiable Information (PT-7)RA-3Risk Assessment (RA-3)LMH
SA-9External System Services (SA-9)LMH
SC-7Boundary Protection (SC-7)LMH
SI-12Information Management and Retention (SI-12)LMH
Cross-Framework Mappings(10)
ID.AM-03ID.AM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule4 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.AM-03ID.AM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(3)
SelectionSelection (one-or-more): interconnection security agreements / information exchange security agreements / memoranda of understanding or agreement / service level agreements / user agreements / non-disclosure agreements / {{ insert: param, ca-03_odp.02 }}
Assignmentorganization-defined type of agreement
Assignmentorganization-defined frequency
Control Enhancements(7)
CA-3(1)Unclassified National Security System Connections (CA-3(1))WCA-3(2)Classified National Security System Connections (CA-3(2))WCA-3(3)Unclassified Non-national Security System Connections (CA-3(3))WCA-3(4)Connections to Public Networks (CA-3(4))WCA-3(5)Restrictions on External System Connections (CA-3(5))WCA-3(6)Transfer Authorizations (CA-3(6))
H
CA-3(7)Transitive Information Exchanges (CA-3(7))