NIST 800-53 REV 5 • ASSESSMENT, AUTHORIZATION, AND MONITORING

CA-3(3)Unclassified Non-national Security System Connections

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

This enhancement was incorporated into the base CA-3 control. It previously addressed connections between unclassified systems that are not national security systems.

Example 1: Document connections between your corporate IT network and a vendor's system using a standard Memorandum of Understanding (MOU) that defines security responsibilities.

Example 2: Maintain a network diagram showing all external connections from your business systems, reviewed quarterly by your IT security team.