Frameworks / FedRAMP High / CA-9 FedRAMP High
CA - Assessment, Authorization, and Monitoring
FedRAMP High CA-9: Internal System Connections Authorize internal connections of components to system; document interface characteristics.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 318 controls across 163 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets SOC2-CC6.3 Role-based access and least privilege are enforced SOC2-CC6.6 Measures against threats outside system boundaries are implemented SOC2-CC6.7 Transmission of data is restricted to authorized users SOC2-CC7.4 Responds to identified security incidents through defined procedures SOC2-CC8.1 Change management processes are in place CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory CIS-12.4 Establish and Maintain Architecture Diagram(s) CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-13.9 Deploy Port-Level Access Control CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C RG5.71-C.3 Cyber Security Training RG5.71-C.5 Recovery and Restoration RG5.71-C.6 Configuration Management 1.2.1 NSC configuration standards defined 1.2.2 Changes to NSC reviewed and approved 1.2.3 Network diagrams maintained 1.2.5 Services, protocols, ports inventoried and justified 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used, 1.2 Operating System Privileged Account Control 1.3 Virtualisation Platform Protection 3.3 Configure Data Access Control Lists DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management RMD-1 Reference Data Management NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-5 Security of Processing, Breach Notification, and DPIA ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training PICSGMP-5 Chapter 5: Production Operations and Material Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training NS-1 Establish network segmentation boundaries NS-2 Secure cloud services with network controls C5-AM-03 Commissioning of Hardware C5-COS-02 Security requirements for connections in the Cloud Service Provider's network FDBR-702 Definitions (§501.702) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 6.5 Preparing and Distributing Audit Report 6.7 Conducting Audit Follow-up STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training C1 Organizational Boundary C3 Scope 1 and 2 Coverage 4.4.1 Resources, Roles, Responsibility, and Authority AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment CPG-6.B Supply Chain Incident Reporting R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10) FFIEC-05 Roles and responsibilities definition ICP-1 Objectives, Powers and Responsibilities of the Supervisor 8.22 Segregation of networks 6.7 Conducting Audit Follow-up PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OSSFSC-1 Branch Protection, Code Review, and Repository Governance PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices) PSPF24-1 Security Culture, Governance, Risk Management RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) SUPCHAIN-1 Build Integrity - Source, Build, Provenance SCA-S2 Interpretation and Definitions SWE-2 Relationship to GDPR FADP-5 Definitions (Article 5) UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11) W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier) SO2.2 Digital health architecture blueprint Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CA - Assessment, Authorization, and Monitoring You are reading one control. How much of FedRAMP High have you already done? FedRAMP High CA-9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.
Query this from an agent The graph holds this control, the 318 it maps to, and the evidence behind each claim, over MCP and REST.