Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

What is an adequate list of mandatory security requirements based on Public Law and other regulation that Civilian agencies should use as a baseline for Certification & Accreditation (C&A)?

0
Posted

What is an adequate list of mandatory security requirements based on Public Law and other regulation that Civilian agencies should use as a baseline for Certification & Accreditation (C&A)?

0

A. OMB Circular A-130 requires a management official authorize in writing the use of each general support system or major application based on the implementation of its security plan before beginning or significantly changing processing in the system. Use of the system shall be re-authorized at least every three years. NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems provides guidance on the certification and accreditation process.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123