Assessment, Authorization and Monitoring (CA) Family
The Assessment, Authorization and Monitoring (CA) family is one of the groups of security and privacy controls maintained by NIST in SP 800-53. It covers the activities an organization uses to check whether its system controls are working, to formally approve a system for operation, and to keep watching the system over time. In short, it addresses how a system gets assessed, gets authorized, and stays monitored once it is running.
The CA family is a control family within NIST SP 800-53 (Revision 5) that addresses the processes for assessing the effectiveness of implemented controls, authorizing systems and services for operation, and conducting ongoing (continuous) monitoring. Constituent controls in Rev. 5 include CA-1 (Policy and Procedures), and, among others, controls addressing control assessments, information exchange, plans of action and milestones, authorization, continuous monitoring, CA-8 (Penetration Testing), and CA-9 (Internal System Connections); practitioners should consult the current authoritative NIST publication for the complete and up-to-date enumeration and control text. Documentation associated with this family generally records how a system is assessed for control effectiveness, authorized for operation, and continuously monitored, typically supported by a system-level continuous monitoring strategy aligned with any organization-level strategy. Note that authorization outputs such as an ATO are time-bound and subject to continuous monitoring rather than permanent, and that assessment (determining control effectiveness) is distinct from authorization (the risk-based decision to operate). This entry describes the CA family conceptually and does not cover agency-specific tailoring, baseline selection, or implementation details, which readers should verify against the applicable revision of NIST SP 800-53 and their governing authority's guidance.
Why it matters
The CA family sits at the heart of any risk-based approach to operating information systems because it connects three distinct but related activities: assessing whether controls actually work, making a formal risk-based decision to authorize a system for operation, and continuously monitoring that system after it goes live. A common and consequential mistake is treating an Authority to Operate (ATO) as a permanent credential. Authorization outputs are time-bound and remain contingent on ongoing monitoring; a system that was acceptable at authorization can drift out of an acceptable risk posture as its environment, threats, and configuration change. Equally important is the distinction between assessment (determining whether controls are effective) and authorization (the risk-based decision to operate). Conflating the two obscures accountability for who determines control effectiveness versus who accepts residual risk.
Who it's relevant to
Inside CA
Common questions
Answers to the questions practitioners most commonly ask about CA.