FedRAMP High
CA - Assessment, Authorization, and Monitoring

FedRAMP High CA-6: Authorization

Senior official authorizes system; reauthorize every three years or upon significant change.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 22 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-P28 Risk Assessment Before Providing a Material Service to Another Party

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC1.2 COSO principle 2: Board exercises oversight responsibility
  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • CBPR-PR-34 Risk assessments and third party certifications
  • CPS220-20 Annual Board Risk Management Declaration

APRA CPS 234 · 1 control

  • CPS234-13 Board Responsibility for Information Security
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

C5 (Germany) · 1 control

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

DORA · 1 control

ISO 22301:2019 · 1 control

  • 9.3 Management review

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security

ISO 27701:2019 · 1 control

NIS2 Directive · 1 control

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA - Assessment, Authorization, and Monitoring

You are reading one control. How much of FedRAMP High have you already done?

FedRAMP High CA-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.

Query this from an agent

The graph holds this control, the 22 it maps to, and the evidence behind each claim, over MCP and REST.