CA-7(1): Independent Assessment
CSF v1.1 References:
- NIST Special Publication 800-53 Revision 4:
- CA-7(1): Independent Assessment
Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
Organizations maximize the value of control assessments by requiring that assessments be conducted by assessors with appropriate levels of independence. The level of required independence is based on organizational continuous monitoring strategies. Assessor independence provides a degree of impartiality to the monitoring process. To achieve such impartiality, assessors do not create a mutual or conflicting interest with the organizations where the assessments are being conducted, assess their own work, act as management or employees of the organizations they are serving, or place themselves in advocacy positions for the organizations acquiring their services.