Skip to content

CA-6: Authorization

An OSCAL Control

Statement

    • a.

      Assign a senior official as the authorizing official for the system;

    • b.

      Assign a senior official as the authorizing official for common controls available for inheritance by organizational systems;

    • c.

      Ensure that the authorizing official for the system, before commencing operations:

      • 1.

        Accepts the use of common controls inherited by the system; and

      • 2.

        Authorizes the system to operate;

    • d.

      Ensure that the authorizing official for common controls authorizes the use of those controls for inheritance by organizational systems;

    • e.

      Update the authorizations .

      • (e) Guidance:

        Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F and according to FedRAMP Significant Change Policies and Procedures. The service provider describes the types of changes to the information system or the environment of operations that would impact the risk posture. The types of changes are approved and accepted by the JAB/AO.