Continuous Monitoring
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-7 — Continuous Monitoring. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions. Automation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as AC-2g, AC-2(7), AC-2(12)(a), AC-2(7)(b), AC-2(7)(c), AC-17(1), AT-4a, AU-13, AU-13(1), AU-13(2), CM-3f, CM-6d, CM-11c, IR-5, MA-2b, MA-3a, MA-4a, PE-3d, PE-6, PE-14b, PE-16, PE-20, PM-6, PM-23, PM-31, PS-7e, SA-9c, SR-4, SC-5(3)(b), SC-7a, SC-7(24)(b), SC-18b, SC-43b , and SI-4.
Enhancements NIST SOURCE
CA-7(1) Independent Assessment LOW ✓ MODERATE ✓ HIGH
Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
Discussion
Organizations maximize the value of control assessments by requiring that assessments be conducted by assessors with appropriate levels of independence. The level of required independence is based on organizational continuous monitoring strategies. Assessor independence provides a degree of impartiality to the monitoring process. To achieve such impartiality, assessors do not create a mutual or conflicting interest with the organizations where the assessments are being conducted, assess their own work, act as management or employees of the organizations they are serving, or place themselves in advocacy positions for the organizations acquiring their services.
CA-7(2) Types of Assessments WITHDRAWN
Withdrawn. Incorporated into CA-2.
CA-7(3) Trend Analyses LOW MODERATE HIGH
Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in the continuous monitoring process need to be modified based on empirical data.
Discussion
Trend analyses include examining recent threat information that addresses the types of threat events that have occurred in the organization or the Federal Government, success rates of certain types of attacks, emerging vulnerabilities in technologies, evolving social engineering techniques, the effectiveness of configuration settings, results from multiple control assessments, and findings from Inspectors General or auditors.
CA-7(4) Risk Monitoring ✓ LOW ✓ MODERATE ✓ HIGH
Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:
- (a) Effectiveness monitoring;
- (b) Compliance monitoring; and
- (c) Change monitoring.
Discussion
Risk monitoring is informed by the established organizational risk tolerance. Effectiveness monitoring determines the ongoing effectiveness of the implemented risk response measures. Compliance monitoring verifies that required risk response measures are implemented. It also verifies that security and privacy requirements are satisfied. Change monitoring identifies changes to organizational systems and environments of operation that may affect security and privacy risk.
CA-7(5) Consistency Analysis LOW MODERATE HIGH
Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [organization-defined actions].
Discussion
Security and privacy controls are often added incrementally to a system. As a result, policies for selecting and implementing controls may be inconsistent, and the controls could fail to work together in a consistent or coordinated manner. At a minimum, the lack of consistency and coordination could mean that there are unacceptable security and privacy gaps in the system. At worst, it could mean that some of the controls implemented in one location or by one component are actually impeding the functionality of other controls (e.g., encrypting internal network traffic can impede monitoring). In other situations, failing to consistently monitor all implemented network protocols (e.g., a dual stack of IPv4 and IPv6) may create unintended vulnerabilities in the system that could be exploited by adversaries. It is important to validate—through testing, monitoring, and analysis—that the implemented controls are operating in a consistent, coordinated, non-interfering manner.
CA-7(6) Automation Support for Monitoring LOW MODERATE HIGH
Ensure the accuracy, currency, and availability of monitoring results for the system using [automated mechanisms].
Discussion
Using automated tools for monitoring helps to maintain the accuracy, currency, and availability of monitoring information which in turns helps to increase the level of ongoing awareness of the system security and privacy posture in support of organizational risk management decisions.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CA-7 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- system-level metrics to be monitored are defined;
- frequencies at which to monitor control effectiveness are defined;
- frequencies at which to assess control effectiveness are defined;
- personnel or roles to whom the security status of the system is reported are defined;
- frequency at which the security status of the system is reported is defined;
- personnel or roles to whom the privacy status of the system is reported are defined;
- frequency at which the privacy status of the system is reported is defined;
- a system-level continuous monitoring strategy is developed;
- system-level continuous monitoring is implemented in accordance with the organization-level continuous monitoring strategy;
- system-level continuous monitoring includes establishment of the following system-level metrics to be monitored: <CA-07_ODP[01] system-level metrics>;
- system-level continuous monitoring includes established <CA-07_ODP[02] frequencies> for monitoring;
- system-level continuous monitoring includes established <CA-07_ODP[03] frequencies> for assessment of control effectiveness;
- system-level continuous monitoring includes ongoing control assessments in accordance with the continuous monitoring strategy;
- system-level continuous monitoring includes ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
- system-level continuous monitoring includes correlation and analysis of information generated by control assessments and monitoring;
- system-level continuous monitoring includes response actions to address the results of the analysis of control assessment and monitoring information;
- system-level continuous monitoring includes reporting the security status of the system to <CA-07_ODP[04] personnel or roles> <CA-07_ODP[05] frequency>;
- system-level continuous monitoring includes reporting the privacy status of the system to <CA-07_ODP[06] personnel or roles> <CA-07_ODP[07] frequency>.
Examine
[SELECT FROM: Assessment, authorization, and monitoring policy; organizational continuous monitoring strategy; system-level continuous monitoring strategy; procedures addressing continuous monitoring of system controls; procedures addressing configuration management; control assessment report; plan of action and milestones; system monitoring records; configuration management records; impact analyses; status reports; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with continuous monitoring responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators].
Test
[SELECT FROM: Mechanisms implementing continuous monitoring; mechanisms supporting response actions to address assessment and monitoring results; mechanisms supporting security and privacy status reporting].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CA-7. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Assessment, authorization, and monitoring policy
- organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- plan of action and milestones
- system security plan
- privacy plan
Configuration
- procedures addressing configuration management
- configuration management records
Testing
- Mechanisms implementing continuous monitoring
- mechanisms supporting response actions to address assessment and monitoring results
- mechanisms supporting security and privacy status reporting
Other Records
- procedures addressing continuous monitoring of system controls
- control assessment report
- system monitoring records
- impact analyses
- status reports
- other relevant documents or records