NIST SP 800-53 Rev 5 MODERATE
CA Assessment, Authorization, and Monitoring

NIST SP 800-53 Rev 5 MODERATE CA-3: Information Exchange

Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.

What else in your programme already covers this

This control maps to 31 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 4 controls

  • 12.5.2 PCI DSS scope documented and confirmed annually
  • 12.8.1 Third-party service provider inventory
  • 12.8.2 Written agreements with TPSPs
  • 12.8.4 TPSP compliance monitored

APPI · 3 controls

  • APPI-A25 Supervision of Trustees
  • APPI-A29 Records When Providing Personal Data to a Third Party
  • APPI-A30 Confirmation and Records When Receiving Personal Data from a Third Party

C5 (Germany) · 3 controls

  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • C5-OIS-03 Interfaces and Dependencies
  • C5-PI-01 Documentation and safety of input and output interfaces

ISO 27001:2022 · 3 controls

  • 5.14 Information transfer
  • 5.20 Addressing information security within supplier agreements
  • 5.22 Monitoring, review and change management of supplier services

SOC 2 · 2 controls

  • SOC2-CC6.7 Transmission of data is restricted to authorized users
  • SOC2-P6.4 Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed
  • ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners
  • SEC03-BP09 Share resources securely with a third party
  • AUCDR-PS-8 Privacy Safeguard 8 - Overseas disclosure of CDR data
  • ASBv3-NS-9 Connect on-premises or cloud network privately

DORA · 1 control

ISO 27002:2022 · 1 control

  • 5.14 Information transfer

ISO 27701:2019 · 1 control

  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA Assessment, Authorization, and Monitoring

Query this from an agent

The graph holds this control, the 31 it maps to, and the evidence behind each claim, over MCP and REST.