STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

CA-9

Assessment, Authorization, and MonitoringRev 5organization

Internal System Connections

Baselines:LowModerateHigh

Control Statement

a. Authorize internal connections of [Assignment: system components] to the system; b. Document, for each internal connection, the interface characteristics, security and privacy requirements, and the nature of the information communicated; c. Terminate internal system connections after [Assignment: conditions] ; and d. Review [Assignment: frequency] the continued need for each internal connection.

Supplemental Guidance

Internal system connections are connections between organizational systems and separate constituent system components (i.e., connections between components that are part of the same system) including components used for system development. Intra-system connections include connections with mobile devices, notebook and desktop computers, tablets, printers, copiers, facsimile machines, scanners, sensors, and servers. Instead of authorizing each internal system connection individually, organizations can authorize internal connections for a class of system components with common characteristics and/or configurations, including printers, scanners, and copiers with a specified processing, transmission, and storage capability or smart phones and tablets with a specific baseline configuration. The continued need for an internal system connection is reviewed from the perspective of whether it provides support for organizational missions or business functions.

Related Controls (8)

AC-3AC-4AC-18AC-19CM-2IA-3SC-7SI-12

CCI Identifiers (10)

CCI-002101Authorizes internal connections of organization-defined system components or classes of components to the system.CCI-002102Defines the system components or classes of components that are authorized internal connections to the system.CCI-002104Document, for each internal connection, the security requirements.CCI-002105Document, for each internal connection, the nature of the information communicated.CCI-002103Document, for each internal connection, the interface characteristics.CCI-003891Document, for each internal connection, the privacy requirements.CCI-003892Terminate internal system connections after organization-defined conditions.CCI-003893Defines the conditions for terminating internal system connections.CCI-003894Review on an organization-defined frequency the continued need for each internal connection.

Linked STIG Checks (2)

Across 1 STIGs. Click to expand.

CCI-003895Defines the frequency for reviewing each internal connection.