Under active development Content is continuously updated and improved

CA-2(3)Security Assessments

Management

>Control Description

SECURITY ASSESSMENTS | EXTERNAL ORGANIZATIONS The organization accepts the results of an assessment of organization-defined information system performed by organization-defined external organization when the assessment meets organization-defined requirements.

>Supplemental Guidance

Organizations may often rely on assessments of specific information systems by other (external) organizations. Utilizing such existing assessments (i.e., reusing existing assessment evidence) can significantly decrease the time and resources required for organizational assessments by limiting the amount of independent assessment activities that organizations need to perform. The factors that organizations may consider in determining whether to accept assessment results from external organizations can vary.

Determinations for accepting assessment results can be based on, for example, past assessment experiences one organization has had with another organization, the reputation that organizations have with regard to assessments, the level of detail of supporting assessment documentation provided, or mandates imposed upon organizations by GC legislation and TBS policies, directives, and standards.

Ask AI

Configure your API key to use AI features.