NIST800-CA-3(7) CA-3(7) Information Exchange | Transitive Information Exchanges
NIST800-CA-3(7) in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
CA-3(7) Information Exchange | Transitive Information Exchanges. (a) Identify transitive (downstream) information exchanges with other systems through the systems identified in CA-3a; and (b) Take measures to ensure that transitive (downstream) information exchanges cease when the controls on identified transitive (downstream) systems cannot be verified or validated.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for NIST800-CA-3(7) yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: CA - Assessment, Authorization, and Monitoring), in our words, not a statement of the standard and not binding on an assessor.
- the security-assessment report
- the authorization decision
- the continuous-monitoring records