Control statement
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:
- a.Establishing the following system-level metrics to be monitored: [Organization-defined: system-level metrics];
- b.Establishing [Organization-defined: frequencies] for monitoring and [Organization-defined: frequencies] for assessment of control effectiveness;
- c.Ongoing control assessments in accordance with the continuous monitoring strategy;
- d.Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
- e.Correlation and analysis of information generated by control assessments and monitoring;
- f.Response actions to address results of the analysis of control assessment and monitoring information; and
- g.Reporting the security and privacy status of the system to [Organization-defined: organization-defined personnel or roles] [Organization-defined: organization-defined frequency].
Discussion
Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions. Automation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as [AC-2g](#ac-2_smt.g), [AC-2(7)](#ac-2.7), [AC-2(12)(a)](#ac-2.12_smt.a), [AC-2(7)(b)](#ac-2.7_smt.b), [AC-2(7)(c)](#ac-2.7_smt.c), [AC-17(1)](#ac-17.1), [AT-4a](#at-4_smt.a), [AU-13](#au-13), [AU-13(1)](#au-13.1), [AU-13(2)](#au-13.2), [CM-3f](#cm-3_smt.f), [CM-6d](#cm-6_smt.d), [CM-11c](#cm-11_smt.c), [IR-5](#ir-5), [MA-2b](#ma-2_smt.b), [MA-3a](#ma-3_smt.a), [MA-4a](#ma-4_smt.a), [PE-3d](#pe-3_smt.d), [PE-6](#pe-6), [PE-14b](#pe-14_smt.b), [PE-16](#pe-16), [PE-20](#pe-20), [PM-6](#pm-6), [PM-23](#pm-23), [PM-31](#pm-31), [PS-7e](#ps-7_smt.e), [SA-9c](#sa-9_smt.c), [SR-4](#sr-4), [SC-5(3)(b)](#sc-5.3_smt.b), [SC-7a](#sc-7_smt.a), [SC-7(24)(b)](#sc-7.24_smt.b), [SC-18b](#sc-18_smt.b), [SC-43b](#sc-43_smt.b) , and [SI-4](#si-4).
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Continuous Monitoring as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to assessment independence, authorization evidence, remediation, and continuous monitoring.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- assessment plans and reports
- plans of action and milestones
- authorization decisions and risk acceptances
- continuous monitoring results
Common failure patterns
- control status based only on owner assertion
- findings closed without evidence
- assessment scope that misses inherited services
- monitoring data disconnected from authorization decisions
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CA-07[01]a system-level continuous monitoring strategy is developed;
- CA-07[02]system-level continuous monitoring is implemented in accordance with the organization-level continuous monitoring strategy;
- CA-07a.system-level continuous monitoring includes establishment of the following system-level metrics to be monitored: [Organization-defined: system-level metrics];
- CA-07b.
- CA-07b.[01]system-level continuous monitoring includes established [Organization-defined: frequencies] for monitoring;
- CA-07b.[02]system-level continuous monitoring includes established [Organization-defined: frequencies] for assessment of control effectiveness;
- CA-07c.system-level continuous monitoring includes ongoing control assessments in accordance with the continuous monitoring strategy;
- CA-07d.system-level continuous monitoring includes ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
- CA-07e.system-level continuous monitoring includes correlation and analysis of information generated by control assessments and monitoring;
- CA-07f.system-level continuous monitoring includes response actions to address the results of the analysis of control assessment and monitoring information;
- CA-07g.
- CA-07g.[01]system-level continuous monitoring includes reporting the security status of the system to [Organization-defined: personnel or roles] [Organization-defined: frequency];
- CA-07g.[02]system-level continuous monitoring includes reporting the privacy status of the system to [Organization-defined: personnel or roles] [Organization-defined: frequency].
Examine
- Assessment, authorization, and monitoring policy
- organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- procedures addressing continuous monitoring of system controls
- procedures addressing configuration management
- control assessment report
- plan of action and milestones
- system monitoring records
- configuration management records
- impact analyses
- status reports
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with continuous monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
Test
- Mechanisms implementing continuous monitoring
- mechanisms supporting response actions to address assessment and monitoring results
- mechanisms supporting security and privacy status reporting
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CA-7(1) — Independent Assessment
Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
Official discussion
Organizations maximize the value of control assessments by requiring that assessments be conducted by assessors with appropriate levels of independence. The level of required independence is based on organizational continuous monitoring strategies. Assessor independence provides a degree of impartiality to the monitoring process. To achieve such impartiality, assessors do not create a mutual or conflicting interest with the organizations where the assessments are being conducted, assess their own work, act as management or employees of the organizations they are serving, or place themselves in advocacy positions for the organizations acquiring their services.
Assessment objectives and methods
independent assessors or assessment teams are employed to monitor the controls in the system on an ongoing basis.
Examine
- Assessment, authorization, and monitoring policy
- organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- procedures addressing continuous monitoring of system controls
- control assessment report
- plan of action and milestones
- system monitoring records
- impact analyses
- status reports
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with continuous monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
CA-7(2) — Types of Assessments
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CA-7(3) — Trend Analyses
Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in the continuous monitoring process need to be modified based on empirical data.
Official discussion
Trend analyses include examining recent threat information that addresses the types of threat events that have occurred in the organization or the Federal Government, success rates of certain types of attacks, emerging vulnerabilities in technologies, evolving social engineering techniques, the effectiveness of configuration settings, results from multiple control assessments, and findings from Inspectors General or auditors.
Assessment objectives and methods
- CA-07(03)[01]trend analysis is employed to determine if control implementations used in the continuous monitoring process need to be modified based on empirical data;
- CA-07(03)[02]trend analysis is employed to determine if the frequency of continuous monitoring activities used in the continuous monitoring process needs to be modified based on empirical data;
- CA-07(03)[03]trend analysis is employed to determine if the types of activities used in the continuous monitoring process need to be modified based on empirical data.
Examine
- Organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- assessment, authorization, and monitoring policy
- procedures addressing continuous monitoring of system controls
- privacy controls
- assessment report
- plan of action and milestones
- system monitoring records
- impact analyses
- status reports
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with continuous monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms supporting trend analyses
CA-7(4) — Risk Monitoring
Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:
- (a)Effectiveness monitoring;
- (b)Compliance monitoring; and
- (c)Change monitoring.
Official discussion
Risk monitoring is informed by the established organizational risk tolerance. Effectiveness monitoring determines the ongoing effectiveness of the implemented risk response measures. Compliance monitoring verifies that required risk response measures are implemented. It also verifies that security and privacy requirements are satisfied. Change monitoring identifies changes to organizational systems and environments of operation that may affect security and privacy risk.
Assessment objectives and methods
risk monitoring is an integral part of the continuous monitoring strategy;
- CA-07(04)(a)effectiveness monitoring is included in risk monitoring;
- CA-07(04)(b)compliance monitoring is included in risk monitoring;
- CA-07(04)(c)change monitoring is included in risk monitoring.
Examine
- Assessment, authorization, and monitoring policy
- organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- procedures addressing continuous monitoring of system controls
- assessment report
- plan of action and milestones
- system monitoring records
- impact analyses
- status reports
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with continuous monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms supporting risk monitoring
CA-7(5) — Consistency Analysis
Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [Organization-defined: organization-defined actions].
Official discussion
Security and privacy controls are often added incrementally to a system. As a result, policies for selecting and implementing controls may be inconsistent, and the controls could fail to work together in a consistent or coordinated manner. At a minimum, the lack of consistency and coordination could mean that there are unacceptable security and privacy gaps in the system. At worst, it could mean that some of the controls implemented in one location or by one component are actually impeding the functionality of other controls (e.g., encrypting internal network traffic can impede monitoring). In other situations, failing to consistently monitor all implemented network protocols (e.g., a dual stack of IPv4 and IPv6) may create unintended vulnerabilities in the system that could be exploited by adversaries. It is important to validate—through testing, monitoring, and analysis—that the implemented controls are operating in a consistent, coordinated, non-interfering manner.
Organization-defined parameters (3)
Assessment objectives and methods
- CA-07(05)[01][Organization-defined: actions] are employed to validate that policies are established;
- CA-07(05)[02][Organization-defined: actions] are employed to validate that implemented controls are operating in a consistent manner.
Examine
- Assessment, authorization, and monitoring policy
- organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- procedures addressing continuous monitoring of system security controls
- assessment report
- plan of action and milestones
- system monitoring records
- security impact analyses
- status reports
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with continuous monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms supporting consistency analyses
CA-7(6) — Automation Support for Monitoring
Ensure the accuracy, currency, and availability of monitoring results for the system using [Organization-defined: automated mechanisms].
Official discussion
Using automated tools for monitoring helps to maintain the accuracy, currency, and availability of monitoring information which in turns helps to increase the level of ongoing awareness of the system security and privacy posture in support of organizational risk management decisions.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: automated mechanisms] are used to ensure the accuracy, currency, and availability of monitoring results for the system.
Examine
- Assessment, authorization, and monitoring policy
- organizational continuous monitoring strategy
- system-level continuous monitoring strategy
- procedures addressing continuous monitoring of system controls
- assessment report
- plan of action and milestones
- system monitoring records
- impact analyses
- status reports
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with continuous monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms supporting automated monitoring
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.