Skip to main content
Category: Security Controls & Tailoring

Assessment, Authorization and Monitoring (CA) Family

Also known as: CA, CA Control Family, Assessment, Authorization, and Monitoring Controls, Security Assessment and Authorization (legacy usage)
Simply put

The Assessment, Authorization and Monitoring (CA) family is one of the groups of security and privacy controls maintained by NIST in SP 800-53. It covers the activities an organization uses to check whether its system controls are working, to formally approve a system for operation, and to keep watching the system over time. In short, it addresses how a system gets assessed, gets authorized, and stays monitored once it is running.

Formal definition

The CA family is a control family within NIST SP 800-53 (Revision 5) that addresses the processes for assessing the effectiveness of implemented controls, authorizing systems and services for operation, and conducting ongoing (continuous) monitoring. Constituent controls in Rev. 5 include CA-1 (Policy and Procedures), and, among others, controls addressing control assessments, information exchange, plans of action and milestones, authorization, continuous monitoring, CA-8 (Penetration Testing), and CA-9 (Internal System Connections); practitioners should consult the current authoritative NIST publication for the complete and up-to-date enumeration and control text. Documentation associated with this family generally records how a system is assessed for control effectiveness, authorized for operation, and continuously monitored, typically supported by a system-level continuous monitoring strategy aligned with any organization-level strategy. Note that authorization outputs such as an ATO are time-bound and subject to continuous monitoring rather than permanent, and that assessment (determining control effectiveness) is distinct from authorization (the risk-based decision to operate). This entry describes the CA family conceptually and does not cover agency-specific tailoring, baseline selection, or implementation details, which readers should verify against the applicable revision of NIST SP 800-53 and their governing authority's guidance.

Why it matters

The CA family sits at the heart of any risk-based approach to operating information systems because it connects three distinct but related activities: assessing whether controls actually work, making a formal risk-based decision to authorize a system for operation, and continuously monitoring that system after it goes live. A common and consequential mistake is treating an Authority to Operate (ATO) as a permanent credential. Authorization outputs are time-bound and remain contingent on ongoing monitoring; a system that was acceptable at authorization can drift out of an acceptable risk posture as its environment, threats, and configuration change. Equally important is the distinction between assessment (determining whether controls are effective) and authorization (the risk-based decision to operate). Conflating the two obscures accountability for who determines control effectiveness versus who accepts residual risk.

Who it's relevant to

Authorizing Officials
Authorizing officials rely on the CA family to structure the risk-based decision to authorize a system for operation. They should treat the resulting ATO as time-bound and contingent on continuous monitoring rather than permanent, and should be clear that accepting an authorization is distinct from the assessment that determined control effectiveness.
Information System Security Managers and Security Officers
These practitioners implement and maintain the CA controls, including developing a system-level continuous monitoring strategy aligned with the organization-level strategy and maintaining documentation of how systems are assessed, authorized, and monitored. They confirm the current control enumeration against the applicable revision of NIST SP 800-53 and any tailoring imposed by their governing authority.
Assessors and Auditors
Assessors evaluate whether implemented controls are effective, producing the findings that feed authorization decisions and plans of action and milestones. Distinguishing their assessment role from the authorization decision is essential, as is verifying that assessment activities reflect the control text of the applicable NIST SP 800-53 revision rather than a superseded version.
Compliance Officers and Program Managers
Those overseeing compliance programs use the CA family to ensure that authorization and continuous monitoring obligations are met on an ongoing basis, not only at initial authorization. They should recognize that agencies and organizations issue their own implementing procedures under NIST guidance, and that satisfying the CA controls documents a risk process rather than guaranteeing that a system is secure.

Inside CA

CA-1 (Policy and Procedures)
Establishes and maintains the organization-level assessment, authorization, and monitoring policy and the procedures needed to implement the family's controls. As in other NIST SP 800-53 families, this control generally requires periodic review and update, and it frames how the remaining CA controls are governed.
CA-2 (Control Assessments)
Addresses the assessment of security and privacy controls to determine whether they are implemented correctly, operating as intended, and producing the desired outcome. Assessments are typically documented in assessment plans and results such as a security assessment report (SAR).
CA-3 (Information Exchange)
Covers the authorization and management of exchanges of information between systems, including the agreements that document security and privacy requirements for those connections. Note that this control was formerly oriented around interconnection security agreements and its scope has evolved across revisions.
CA-5 (Plan of Action and Milestones)
Requires development and maintenance of a plan of action and milestones (POA&M) to document planned remediation of weaknesses or deficiencies identified during assessments and monitoring.
CA-6 (Authorization)
Addresses the senior official's risk-based decision to authorize a system to operate (or to authorize common controls). An authorization decision, commonly an Authority to Operate (ATO), is time-bound and dependent on ongoing conditions rather than permanent.
CA-7 (Continuous Monitoring)
Establishes an ongoing monitoring strategy and program to maintain awareness of the security and privacy posture of the system over time, informing whether the authorization remains valid.
CA-8 (Penetration Testing)
Addresses the conduct of penetration testing to identify exploitable vulnerabilities. Its applicability is often determined by tailoring, impact level, and organizational or agency-specific requirements rather than being universally mandated.
CA-9 (Internal System Connections)
Covers the authorization of internal connections of system components or classes of components, as distinct from external information exchanges handled under CA-3.

Common questions

Answers to the questions practitioners most commonly ask about CA.

Does an Authority to Operate (ATO) issued through the CA family controls remain valid indefinitely once granted?
No. An ATO is a time-bound, risk-based decision by an authorizing official, not a permanent status. The CA family pairs authorization (CA-6) with ongoing assessment (CA-2) and continuous monitoring (CA-7), reflecting that the security posture underlying an authorization can change as systems, threats, and controls evolve. Many implementations tie continued operation to an active continuous monitoring program and periodic reauthorization, and some agencies use ongoing authorization approaches in place of fixed expiration dates. Readers should confirm the specific authorization duration, reauthorization triggers, and continuous monitoring expectations against their governing policy and the applicable revision of NIST SP 800-53.
Does completing the assessment activities in the CA family mean a system is secure and compliant?
Not on its own. Assessment (CA-2) determines whether controls are implemented correctly and operating as intended at a point in time; it is distinct from authorization (CA-6), which is the risk acceptance decision, and from the actual security state of the system. Satisfying assessment and authorization requirements demonstrates a documented, risk-informed process, but compliance with a control family is not equivalent to being secure. Residual risk, findings tracked in plans of action and milestones, and changes occurring after the assessment window all affect the true posture. Continuous monitoring (CA-7) is what helps keep the picture current between assessments.
Which controls make up the Assessment, Authorization, and Monitoring (CA) family?
In NIST SP 800-53, the CA family generally includes CA-1 (Policy and Procedures), CA-2 (Control Assessments), CA-3 (Information Exchange), CA-5 (Plan of Action and Milestones), CA-6 (Authorization), CA-7 (Continuous Monitoring), CA-8 (Penetration Testing), and CA-9 (Internal System Connections). Which controls and enhancements actually apply to a given system depends on the selected baseline and any agency or program tailoring. Because control designations and content can change across revisions, confirm the current set against the applicable revision of the official publication.
Who is subject to the CA family requirements?
The CA family is part of NIST SP 800-53 and is applied broadly across federal information systems under FISMA, which applies government-wide, including DoD systems that are not national security systems, as well as civilian agency systems. Its use also appears in authorization contexts such as FedRAMP for cloud services and DoD Risk Management Framework implementations. Requirements for classified or national security systems, and obligations for state, local, tribal, and territorial entities, may differ. Readers should verify how the family applies within their specific authorization boundary and governing policy.
How does the CA family relate to a plan of action and milestones (POA&M)?
CA-5 addresses the plan of action and milestones, which documents weaknesses or deficiencies identified during control assessments (CA-2) and the planned corrective actions and timelines. The POA&M generally feeds the authorizing official's risk determination under CA-6 and is maintained and reviewed as part of continuous monitoring under CA-7. The specific format, update frequency, and tracking expectations for POA&Ms are often set by agency or program policy, so confirm those details against your applicable requirements.
What is the difference between CA-3 (Information Exchange) and CA-9 (Internal System Connections)?
CA-3 addresses exchanges of information between systems, which in many implementations involves agreements governing connections that cross authorization boundaries. CA-9 addresses internal system connections between components within a single system boundary. The distinction matters when scoping which connections require formal agreements versus internal documentation. How organizations draw the boundary between these two controls can vary with system architecture and agency interpretation, so confirm scoping decisions against your system security documentation and the applicable revision of the guidance.

Common misconceptions

An Authority to Operate (ATO) granted under CA-6 is a permanent approval.
An authorization is a time-bound, risk-based decision that depends on the continued effectiveness of controls. It is sustained through continuous monitoring (CA-7) and can be reevaluated or withdrawn as the system's risk posture changes.
Completing a control assessment (CA-2) is the same as achieving authorization (CA-6).
Assessment and authorization are distinct activities. An assessment determines whether controls are implemented correctly and operating as intended, while authorization is the separate senior-official decision to accept the residual risk and permit operation.
The CA family applies only to civilian agency systems and is separate from defense obligations.
NIST SP 800-53 is used across federal civilian, defense, and other communities, and FISMA applies government-wide, including DoD non-national-security systems. How the CA controls are tailored and how authorization is executed (for example within the DoD RMF process) can differ by community, so practitioners should confirm the applicable baseline and agency guidance.

Best practices

Treat authorization under CA-6 as conditional and maintain an active continuous monitoring program under CA-7 so the authorizing official has current information rather than relying on the point-in-time assessment.
Keep the plan of action and milestones (CA-5) current, with realistic remediation timelines tied to findings from assessments and monitoring, and review it regularly rather than only at authorization.
Clearly separate assessment activities (CA-2) from the authorization decision (CA-6) in your process documentation, ensuring assessor independence where required by your applicable baseline or agency policy.
Distinguish external information exchanges (CA-3) from internal system connections (CA-9), and document the required agreements and authorizations for each accordingly.
Confirm whether penetration testing (CA-8) is required for your system based on tailoring, impact level, and agency-specific direction rather than assuming it is or is not in scope.
Verify the constituent controls, enhancements, and baseline allocations against the current applicable revision of NIST SP 800-53 and any agency or community tailoring (such as DoD RMF) before finalizing implementation.