CA-1: Policy and Procedures
An OSCAL Control
-
-
personnel or roles
personnel or roles to whom the assessment, authorization, and monitoring policy is to be disseminated is/are defined;
-
personnel or roles
personnel or roles to whom the assessment, authorization, and monitoring procedures are to be disseminated is/are defined;
-
official
an official to manage the assessment, authorization, and monitoring policy and procedures is defined;
-
frequency
the frequency at which the current assessment, authorization, and monitoring policy is reviewed and updated is defined;
-
events
events that would require the current assessment, authorization, and monitoring policy to be reviewed and updated are defined;
-
frequency
the frequency at which the current assessment, authorization, and monitoring procedures are reviewed and updated is defined;
-
events
events that would require assessment, authorization, and monitoring procedures to be reviewed and updated are defined;