NIST 800-53 REV 5 • ASSESSMENT, AUTHORIZATION, AND MONITORING
CA-3(3) — Unclassified Non-national Security System Connections
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
This enhancement was incorporated into the base CA-3 control. It previously addressed connections between unclassified systems that are not national security systems.
Example 1: Document connections between your corporate IT network and a vendor's system using a standard Memorandum of Understanding (MOU) that defines security responsibilities.
Example 2: Maintain a network diagram showing all external connections from your business systems, reviewed quarterly by your IT security team.