FedRAMP Controls / CA

CA-3 Information Exchange

Family CA
Baselines moderate
Mapped KSIs 1

Control statement

a. Approve and manage the exchange of information between the system and other systems using {{ insert: param, ca-03_odp.01 }};
    b. Document, as part of each exchange agreement, the interface characteristics, security and privacy requirements, controls, and responsibilities for each system, and the impact level of the information communicated; and
    c. Review and update the agreements {{ insert: param, ca-03_odp.03 }}.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-TPR-04Supply Chain Risk Monitoring
Automatically monitor third party software _information resources_ for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.
Third-Party Information Resources