Continuous Monitoring

✓ LOW ✓ MODERATE ✓ HIGH
5 Enhancements 1 Overlay 51 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:

Discussion (NIST Supplemental Guidance)

Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions. Automation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as AC-2g, AC-2(7), AC-2(12)(a), AC-2(7)(b), AC-2(7)(c), AC-17(1), AT-4a, AU-13, AU-13(1), AU-13(2), CM-3f, CM-6d, CM-11c, IR-5, MA-2b, MA-3a, MA-4a, PE-3d, PE-6, PE-14b, PE-16, PE-20, PM-6, PM-23, PM-31, PS-7e, SA-9c, SR-4, SC-5(3)(b), SC-7a, SC-7(24)(b), SC-18b, SC-43b , and SI-4.

Enhancements NIST SOURCE

CA-7(1) Independent Assessment LOW ✓ MODERATE ✓ HIGH

Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

Discussion

Organizations maximize the value of control assessments by requiring that assessments be conducted by assessors with appropriate levels of independence. The level of required independence is based on organizational continuous monitoring strategies. Assessor independence provides a degree of impartiality to the monitoring process. To achieve such impartiality, assessors do not create a mutual or conflicting interest with the organizations where the assessments are being conducted, assess their own work, act as management or employees of the organizations they are serving, or place themselves in advocacy positions for the organizations acquiring their services.

Open full page for CA-7(1) →
CA-7(2) Types of Assessments WITHDRAWN

Withdrawn. Incorporated into CA-2.

CA-7(3) Trend Analyses LOW MODERATE HIGH

Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in the continuous monitoring process need to be modified based on empirical data.

Discussion

Trend analyses include examining recent threat information that addresses the types of threat events that have occurred in the organization or the Federal Government, success rates of certain types of attacks, emerging vulnerabilities in technologies, evolving social engineering techniques, the effectiveness of configuration settings, results from multiple control assessments, and findings from Inspectors General or auditors.

Open full page for CA-7(3) →
CA-7(4) Risk Monitoring ✓ LOW ✓ MODERATE ✓ HIGH

Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:

  1. (a) Effectiveness monitoring;
  2. (b) Compliance monitoring; and
  3. (c) Change monitoring.
Discussion

Risk monitoring is informed by the established organizational risk tolerance. Effectiveness monitoring determines the ongoing effectiveness of the implemented risk response measures. Compliance monitoring verifies that required risk response measures are implemented. It also verifies that security and privacy requirements are satisfied. Change monitoring identifies changes to organizational systems and environments of operation that may affect security and privacy risk.

Open full page for CA-7(4) →
CA-7(5) Consistency Analysis LOW MODERATE HIGH

Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-defined actions].

Discussion

Security and privacy controls are often added incrementally to a system. As a result, policies for selecting and implementing controls may be inconsistent, and the controls could fail to work together in a consistent or coordinated manner. At a minimum, the lack of consistency and coordination could mean that there are unacceptable security and privacy gaps in the system. At worst, it could mean that some of the controls implemented in one location or by one component are actually impeding the functionality of other controls (e.g., encrypting internal network traffic can impede monitoring). In other situations, failing to consistently monitor all implemented network protocols (e.g., a dual stack of IPv4 and IPv6) may create unintended vulnerabilities in the system that could be exploited by adversaries. It is important to validate—through testing, monitoring, and analysis—that the implemented controls are operating in a consistent, coordinated, non-interfering manner.

Open full page for CA-7(5) →
CA-7(6) Automation Support for Monitoring LOW MODERATE HIGH

Ensure the accuracy, currency, and availability of monitoring results for the system using [automated mechanisms].

Discussion

Using automated tools for monitoring helps to maintain the accuracy, currency, and availability of monitoring information which in turns helps to increase the level of ongoing awareness of the system security and privacy posture in support of organizational risk management decisions.

Open full page for CA-7(6) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CA-7 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. system-level metrics to be monitored are defined;
  2. frequencies at which to monitor control effectiveness are defined;
  3. frequencies at which to assess control effectiveness are defined;
  4. personnel or roles to whom the security status of the system is reported are defined;
  5. frequency at which the security status of the system is reported is defined;
  6. personnel or roles to whom the privacy status of the system is reported are defined;
  7. frequency at which the privacy status of the system is reported is defined;
  8. a system-level continuous monitoring strategy is developed;
  9. system-level continuous monitoring is implemented in accordance with the organization-level continuous monitoring strategy;
  10. system-level continuous monitoring includes establishment of the following system-level metrics to be monitored: <CA-07_ODP[01] system-level metrics>;
  11. system-level continuous monitoring includes established <CA-07_ODP[02] frequencies> for monitoring;
  12. system-level continuous monitoring includes established <CA-07_ODP[03] frequencies> for assessment of control effectiveness;
  13. system-level continuous monitoring includes ongoing control assessments in accordance with the continuous monitoring strategy;
  14. system-level continuous monitoring includes ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
  15. system-level continuous monitoring includes correlation and analysis of information generated by control assessments and monitoring;
  16. system-level continuous monitoring includes response actions to address the results of the analysis of control assessment and monitoring information;
  17. system-level continuous monitoring includes reporting the security status of the system to <CA-07_ODP[04] personnel or roles> <CA-07_ODP[05] frequency>;
  18. system-level continuous monitoring includes reporting the privacy status of the system to <CA-07_ODP[06] personnel or roles> <CA-07_ODP[07] frequency>.

Examine

[SELECT FROM: Assessment, authorization, and monitoring policy; organizational continuous monitoring strategy; system-level continuous monitoring strategy; procedures addressing continuous monitoring of system controls; procedures addressing configuration management; control assessment report; plan of action and milestones; system monitoring records; configuration management records; impact analyses; status reports; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with continuous monitoring responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators].

Test

[SELECT FROM: Mechanisms implementing continuous monitoring; mechanisms supporting response actions to address assessment and monitoring results; mechanisms supporting security and privacy status reporting].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)
  • Included: (4)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (4)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (4)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CA-7. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Assessment, authorization, and monitoring policy
  • organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • plan of action and milestones
  • system security plan
  • privacy plan

Configuration

  • procedures addressing configuration management
  • configuration management records

Testing

  • Mechanisms implementing continuous monitoring
  • mechanisms supporting response actions to address assessment and monitoring results
  • mechanisms supporting security and privacy status reporting

Other Records

  • procedures addressing continuous monitoring of system controls
  • control assessment report
  • system monitoring records
  • impact analyses
  • status reports
  • other relevant documents or records