NIST 800-53 r5 · Controls catalogue · Family CA
CA-6Authorization
Assign a senior official as the authorizing official for the system; Assign a senior official as the authorizing official for common controls available for inheritance by organizational systems; Ensure that the authorizing official for the system, before commencing operations: Accepts the use of common controls inherited by the system; and Authorizes the system to operate; Ensure that the authorizing official for common controls authorizes the use of those controls for inheritance by organizational systems; Update the authorizations {{ insert: param, ca-06_odp }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (4)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Prevents systems from commencing operations without assigned authorizing official approval, addressing missing authorization for critical functions. |
CWE-284 | Improper Access Control | 6,900+ | Requires formal authorization of the system and inherited controls before operation, ensuring access control mechanisms are reviewed and approved. |
CWE-863 | Incorrect Authorization | 3,900+ | The authorization process includes review of common controls and system security, helping detect and correct incorrect authorization implementations. |
CWE-285 | Improper Authorization | 1,500+ | Mandates explicit acceptance and authorization of controls by a senior official, directly reducing improper authorization configurations. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||