FedRAMP Moderate
CA - Assessment, Authorization, and Monitoring

FedRAMP Moderate CA-9: Internal System Connections

Authorize internal connections of components to system; document interface characteristics.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 293 controls across 159 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 7 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

CIS Controls v8 · 5 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-12.4 Establish and Maintain Architecture Diagram(s)
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • RG5.71-C.3 Cyber Security Training
  • RG5.71-C.5 Recovery and Restoration
  • RG5.71-C.6 Configuration Management

PCI DSS 4.0 · 5 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 2.2.2 2.2.2 Vendor default accounts managed

FedRAMP Rev 5 · 4 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance
  • PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training
  • PICSGMP-5 Chapter 5: Production Operations and Material Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights

UK Bribery Act 2010 · 3 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • UKBRIBE-3 Due Diligence on Third Parties
  • 58.1 Scope
  • 58.3 Definitions
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • NS-1 Establish network segmentation boundaries
  • NS-2 Secure cloud services with network controls

C5 (Germany) · 2 controls

  • C5-AM-03 Commissioning of Hardware
  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability
  • GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause9-Performance-Monitoring-InternalAudit-ManagementReview IATF 16949 Clause 9 - Performance Evaluation + Monitoring + Internal Audit + Manufacturing Process Audit + Management Review
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 2 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes
  • IsraelPPL-Scope-5741-1981-Knesset-Amendment13-March2024-BasicLaw-Dignity-Sec1-Right-Privacy Israel Protection of Privacy Law 5741-1981 Scope + Knesset + Amendment No. 13 March 2024 + Basic Law Human Dignity and Liberty + Section 1 Right to Privacy + Constitutional Status + Chapter 1 Infringement of Privacy

MTCS (Singapore) · 2 controls

  • MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles
  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIST SP 800-53 Rev 5 · 2 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border
  • UKGAMBLE-1 Scope and Applicability to Licensees
  • UKGAMBLE-4 Resilience and Incident Response
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment
  • AZ-DPA-2 Article 2 - Basic Concepts
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
  • FFIEC-05 Roles and responsibilities definition
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct

GLBA · 1 control

  • GLBA-Sec6801-PolicyDuty-SafeguardingStandard GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard
  • GLI33-EventWagering-System-Architecture GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management
  • HKMA-CRAF-Domain1-2-Governance-Identification HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment

HKMA SPM · 1 control

  • HKMA-SPM-CG-IC-AC-Governance-Control-Audit HKMA SPM Corporate Governance (CG-1/2/3/5/6), Internal Control (IC-1/5), Auditing (AC-G)
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality
  • 62351-2 Glossary of terms
  • IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

ISMAP (Japan) · 1 control

  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition

ISO 27001:2022 · 1 control

  • 8.22 Segregation of networks

ISO 27002:2022 · 1 control

  • 8.20 Networks security
  • ISO28001-PI-01 Personnel Security Screening

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy

ISO/IEC 27043:2015 · 1 control

  • ISO27043-04 Roles and responsibilities definition
  • 27050-1.4 Terms and definitions

ISO/IEC 27400:2022 · 1 control

  • 27400-3 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions

ISO/SAE 21434 · 1 control

  • ISO21434-04 Roles and responsibilities definition
  • ITAR-Scope-AECA-22USC2778-22CFR120-130-DDTC-USML-21Categories-DefenseArticle-Service-TechnicalData ITAR Scope + Arms Export Control Act (22 USC 2778) + 22 CFR Parts 120-130 + Directorate of Defense Trade Controls (DDTC) + United States Munitions List (USML) 21 Categories + Defense Article/Service/Technical Data Definitions
  • ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members
  • BIPA-SEC5-1 Biometric Identifier Definition

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

  • MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management
  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature

NIST SP 800-123 · 1 control

NIST SP 800-137 · 1 control

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework

NIST SP 800-190 · 1 control

  • CA-9 CA-9 Internal System Connections
  • CA-9 CA-9 Internal System Connections
  • CA-9 CA-9 Internal System Connections
  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

OSFI B-13 · 1 control

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions

OWASP Top 10:2025 · 1 control

  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX

OpenSSF Scorecard · 1 control

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements

PTES · 1 control

  • PTESPHASE-1 Pre-Engagement Interactions and Scoping
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • PSPF24-1 Security Culture, Governance, Risk Management
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • RIDTPPA-1 Scope, Applicability, Definitions
  • SHAREASSESS-1 Information Governance and Risk

SLSA · 1 control

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SCA-S2 Interpretation and Definitions

South Korea ISMS-P · 1 control

  • ISMSP-SYS-04 Vulnerability Management

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • SWE-2 Relationship to GDPR
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • UK-TSA-NET-01 Security Architecture
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA - Assessment, Authorization, and Monitoring

You are reading one control. How much of FedRAMP Moderate have you already done?

FedRAMP Moderate CA-9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP Moderate your existing evidence covers. Hold ISO 27002:2022 and 182 of 323 FedRAMP Moderate controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 348 were rejected on the ISO 27002:2022 pair alone.

Query this from an agent

The graph holds this control, the 293 it maps to, and the evidence behind each claim, over MCP and REST.