NIST SP 800-53 Rev 5
CA - Assessment, Authorization, and Monitoring

NIST SP 800-53 Rev 5 NIST800-CA-6: CA-6 Authorization

a. Assign a senior official as the authorizing official for the system; b. Assign a senior official as the authorizing official for common controls available for inheritance by organizational systems; c. Ensure that the authorizing official for the system, before commencing operations: 1. Accepts the use of common controls inherited by the system; and 2. Authorizes the system to operate; d. Ensure that the authorizing official for common controls authorizes the use of those controls for inheritance by organizational systems; e. Update the authorizations [Assignment: organization-defined frequency].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 39 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

CMMC 2.0 · 4 controls

EU AI Act · 4 controls

SOC 2 · 4 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-P5.1 P5.1 Data subject access

PCI DSS 4.0 · 3 controls

  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • CPS220-02 Board Responsibility for the Risk Management Framework
  • CPS220-20 Annual Board Risk Management Declaration
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-P28 Risk Assessment Before Providing a Material Service to Another Party

APRA CPS 234 · 1 control

  • CPS234-13 Board Responsibility for Information Security
  • IRAP-OUT-2 Authority to Operate decision support
  • ITSG33-RMP-5 Security Assessment and Authorization

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

HIPAA Security Rule · 1 control

ISO/IEC 42001:2023 · 1 control

  • 9.3.2 Management review inputs

NIS2 Directive · 1 control

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation
  • CA-6 CA-6 Authorization
  • CA-6 CA-6 Authorization
  • CA-6 CA-6 Authorization

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA - Assessment, Authorization, and Monitoring

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CA-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.