{"id":1411,"date":"2024-07-24T16:49:55","date_gmt":"2024-07-24T16:49:55","guid":{"rendered":"https:\/\/www.tarleton.edu\/security-controls-catalog\/?page_id=1411"},"modified":"2024-09-06T21:29:18","modified_gmt":"2024-09-06T21:29:18","slug":"ca-3-information-exchange","status":"publish","type":"page","link":"https:\/\/www.tarleton.edu\/security-controls-catalog\/assessment-authorization-and-monitoring-ca\/ca-3-information-exchange\/","title":{"rendered":"CA-3: Information Exchange"},"content":{"rendered":"\n<h1 class=\"wp-block-heading has-large-font-size\">CA-3: Information Exchange<\/h1>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:16px\"><strong>NIST Baseline: &nbsp;<\/strong>Low&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:16px\"><strong>DIR Required By: &nbsp;<\/strong>07\/20\/2023&nbsp;<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" style=\"font-size:16px\"><strong>Review Date: &nbsp;<\/strong>06\/26\/2024&nbsp;<\/h2>\n\n\n\n<ul class=\"wp-block-list its-nested-list\">\n<li>The Tarleton State University (Tarleton) Office of Innovative Technology Solutions (OITS) authorizes all dedicated connections from Tarleton\u2019s information resources to external information systems.&nbsp; Generally, connections are in scope if they are dedicated and (semi)-permanent.&nbsp; This control does not apply to user-controlled, transitory connections (such as email or website browsing).&nbsp;&nbsp;\n<ul class=\"wp-block-list\">\n<li>Interconnection security agreements for non-publicly accessible information must be established with all outside information providers\/consumers.&nbsp;&nbsp;&nbsp;<\/li>\n\n\n\n<li>Each exchange agreement must document:&nbsp;&nbsp;\n<ul class=\"wp-block-list\">\n<li>The purpose of the connection;&nbsp;&nbsp;<\/li>\n\n\n\n<li>The nature of the information communicated including the <a href=\"https:\/\/assets.system.tamus.edu\/files\/policy\/pdf\/so-Security-Standards\/DataClassProtect.pdf\">Texas A&amp;M University System (TAMUS) data classification<\/a>, and <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/fips\/nist.fips.199.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">FIPS 199<\/a> impact levels;\u00a0\u00a0<\/li>\n\n\n\n<li>Interface characteristics including host names or IP addresses, data transfer method, ports, and protocols;&nbsp;&nbsp;<\/li>\n\n\n\n<li>Security and privacy requirements; and&nbsp;&nbsp;<\/li>\n\n\n\n<li>Data transfer frequency.&nbsp;&nbsp;<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>The Tarleton CISO is responsible for ensuring that interconnection security agreements are reviewed periodically.&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator alignfull has-text-color has-tarleton-purple-color has-alpha-channel-opacity has-tarleton-purple-background-color has-background is-style-wide\"\/>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\"><strong>References\/Additional Resources<\/strong><\/h3>\n\n\n\n<p><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/fips\/nist.fips.199.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">FIPS 199<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/assets.system.tamus.edu\/files\/policy\/pdf\/so-Security-Standards\/DataClassProtect.pdf\">TAMUS data classification<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CA-3: Information Exchange NIST Baseline: &nbsp;Low&nbsp; DIR Required By: &nbsp;07\/20\/2023&nbsp; Review Date: &nbsp;06\/26\/2024&nbsp; References\/Additional Resources FIPS 199 TAMUS data classification<\/p>\n","protected":false},"author":1,"featured_media":580,"parent":788,"menu_order":3,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"class_list":["post-1411","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"coauthors":[],"author_meta":{"author_link":"https:\/\/www.tarleton.edu\/security-controls-catalog\/author\/brian-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-2-3\/","display_name":"brian"},"relative_dates":{"created":"Posted 2 years ago","modified":"Updated 2 years ago"},"absolute_dates":{"created":"Posted on July 24, 2024","modified":"Updated on September 6, 2024"},"absolute_dates_time":{"created":"Posted on July 24, 2024 4:49 pm","modified":"Updated on September 6, 2024 9:29 pm"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/comments?post=1411"}],"version-history":[{"count":0,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/1411\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/pages\/788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.tarleton.edu\/security-controls-catalog\/wp-json\/wp\/v2\/media?parent=1411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}