Control statement
a. Approve and manage the exchange of information between the system and other systems using {{ insert: param, ca-03_odp.01 }};
b. Document, as part of each exchange agreement, the interface characteristics, security and privacy requirements, controls, and responsibilities for each system, and the impact level of the information communicated; and
c. Review and update the agreements {{ insert: param, ca-03_odp.03 }}. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-TPR-04 | Supply Chain Risk Monitoring Automatically monitor third party software _information resources_ for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services. | Third-Party Information Resources |