Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CA-7 — Continuous Monitoring

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

6Enhancements
9Parameters
4Baseline memberships
3Assessment methods

CA — Assessment, Authorization, and Monitoring · NIST SP 800-53 Release 5.2.0

LowModerateHighPrivacy
Official NIST control content

Control statement

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:

  1. a.Establishing the following system-level metrics to be monitored: [Organization-defined: system-level metrics];
  2. b.Establishing [Organization-defined: frequencies] for monitoring and [Organization-defined: frequencies] for assessment of control effectiveness;
  3. c.Ongoing control assessments in accordance with the continuous monitoring strategy;
  4. d.Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
  5. e.Correlation and analysis of information generated by control assessments and monitoring;
  6. f.Response actions to address results of the analysis of control assessment and monitoring information; and
  7. g.Reporting the security and privacy status of the system to [Organization-defined: organization-defined personnel or roles] [Organization-defined: organization-defined frequency].
Official NIST discussion

Discussion

Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions. Automation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as [AC-2g](#ac-2_smt.g), [AC-2(7)](#ac-2.7), [AC-2(12)(a)](#ac-2.12_smt.a), [AC-2(7)(b)](#ac-2.7_smt.b), [AC-2(7)(c)](#ac-2.7_smt.c), [AC-17(1)](#ac-17.1), [AT-4a](#at-4_smt.a), [AU-13](#au-13), [AU-13(1)](#au-13.1), [AU-13(2)](#au-13.2), [CM-3f](#cm-3_smt.f), [CM-6d](#cm-6_smt.d), [CM-11c](#cm-11_smt.c), [IR-5](#ir-5), [MA-2b](#ma-2_smt.b), [MA-3a](#ma-3_smt.a), [MA-4a](#ma-4_smt.a), [PE-3d](#pe-3_smt.d), [PE-6](#pe-6), [PE-14b](#pe-14_smt.b), [PE-16](#pe-16), [PE-20](#pe-20), [PM-6](#pm-6), [PM-23](#pm-23), [PM-31](#pm-31), [PS-7e](#ps-7_smt.e), [SA-9c](#sa-9_smt.c), [SR-4](#sr-4), [SC-5(3)(b)](#sc-5.3_smt.b), [SC-7a](#sc-7_smt.a), [SC-7(24)(b)](#sc-7.24_smt.b), [SC-18b](#sc-18_smt.b), [SC-43b](#sc-43_smt.b) , and [SI-4](#si-4).

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined personnel or roles
organization-defined frequency
system-level metricssystem-level metrics to be monitored are defined;
frequenciesfrequencies at which to monitor control effectiveness are defined;
frequenciesfrequencies at which to assess control effectiveness are defined;
personnel or rolespersonnel or roles to whom the security status of the system is reported are defined;
frequencyfrequency at which the security status of the system is reported is defined;
personnel or rolespersonnel or roles to whom the privacy status of the system is reported are defined;
frequencyfrequency at which the privacy status of the system is reported is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Continuous Monitoring as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to assessment independence, authorization evidence, remediation, and continuous monitoring.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • assessment plans and reports
  • plans of action and milestones
  • authorization decisions and risk acceptances
  • continuous monitoring results

Common failure patterns

  • control status based only on owner assertion
  • findings closed without evidence
  • assessment scope that misses inherited services
  • monitoring data disconnected from authorization decisions

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CA-07[01]a system-level continuous monitoring strategy is developed;
  2. CA-07[02]system-level continuous monitoring is implemented in accordance with the organization-level continuous monitoring strategy;
  3. CA-07a.system-level continuous monitoring includes establishment of the following system-level metrics to be monitored: [Organization-defined: system-level metrics];
  4. CA-07b.
    1. CA-07b.[01]system-level continuous monitoring includes established [Organization-defined: frequencies] for monitoring;
    2. CA-07b.[02]system-level continuous monitoring includes established [Organization-defined: frequencies] for assessment of control effectiveness;
  5. CA-07c.system-level continuous monitoring includes ongoing control assessments in accordance with the continuous monitoring strategy;
  6. CA-07d.system-level continuous monitoring includes ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
  7. CA-07e.system-level continuous monitoring includes correlation and analysis of information generated by control assessments and monitoring;
  8. CA-07f.system-level continuous monitoring includes response actions to address the results of the analysis of control assessment and monitoring information;
  9. CA-07g.
    1. CA-07g.[01]system-level continuous monitoring includes reporting the security status of the system to [Organization-defined: personnel or roles] [Organization-defined: frequency];
    2. CA-07g.[02]system-level continuous monitoring includes reporting the privacy status of the system to [Organization-defined: personnel or roles] [Organization-defined: frequency].

Examine

  • Assessment, authorization, and monitoring policy
  • organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • procedures addressing continuous monitoring of system controls
  • procedures addressing configuration management
  • control assessment report
  • plan of action and milestones
  • system monitoring records
  • configuration management records
  • impact analyses
  • status reports
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with continuous monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators

Test

  • Mechanisms implementing continuous monitoring
  • mechanisms supporting response actions to address assessment and monitoring results
  • mechanisms supporting security and privacy status reporting
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CA-7(1) — Independent Assessment

ModerateHigh

Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

Official discussion

Organizations maximize the value of control assessments by requiring that assessments be conducted by assessors with appropriate levels of independence. The level of required independence is based on organizational continuous monitoring strategies. Assessor independence provides a degree of impartiality to the monitoring process. To achieve such impartiality, assessors do not create a mutual or conflicting interest with the organizations where the assessments are being conducted, assess their own work, act as management or employees of the organizations they are serving, or place themselves in advocacy positions for the organizations acquiring their services.

Assessment objectives and methods

independent assessors or assessment teams are employed to monitor the controls in the system on an ongoing basis.

Examine

  • Assessment, authorization, and monitoring policy
  • organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • procedures addressing continuous monitoring of system controls
  • control assessment report
  • plan of action and milestones
  • system monitoring records
  • impact analyses
  • status reports
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with continuous monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities
Official NIST control enhancement

CA-7(2) — Types of Assessments

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CA-7(3) — Trend Analyses

Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in the continuous monitoring process need to be modified based on empirical data.

Official discussion

Trend analyses include examining recent threat information that addresses the types of threat events that have occurred in the organization or the Federal Government, success rates of certain types of attacks, emerging vulnerabilities in technologies, evolving social engineering techniques, the effectiveness of configuration settings, results from multiple control assessments, and findings from Inspectors General or auditors.

Assessment objectives and methods
  1. CA-07(03)[01]trend analysis is employed to determine if control implementations used in the continuous monitoring process need to be modified based on empirical data;
  2. CA-07(03)[02]trend analysis is employed to determine if the frequency of continuous monitoring activities used in the continuous monitoring process needs to be modified based on empirical data;
  3. CA-07(03)[03]trend analysis is employed to determine if the types of activities used in the continuous monitoring process need to be modified based on empirical data.

Examine

  • Organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • assessment, authorization, and monitoring policy
  • procedures addressing continuous monitoring of system controls
  • privacy controls
  • assessment report
  • plan of action and milestones
  • system monitoring records
  • impact analyses
  • status reports
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with continuous monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Mechanisms supporting trend analyses
Official NIST control enhancement

CA-7(4) — Risk Monitoring

LowModerateHighPrivacy

Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:

  1. (a)Effectiveness monitoring;
  2. (b)Compliance monitoring; and
  3. (c)Change monitoring.
Official discussion

Risk monitoring is informed by the established organizational risk tolerance. Effectiveness monitoring determines the ongoing effectiveness of the implemented risk response measures. Compliance monitoring verifies that required risk response measures are implemented. It also verifies that security and privacy requirements are satisfied. Change monitoring identifies changes to organizational systems and environments of operation that may affect security and privacy risk.

Assessment objectives and methods

risk monitoring is an integral part of the continuous monitoring strategy;

  1. CA-07(04)(a)effectiveness monitoring is included in risk monitoring;
  2. CA-07(04)(b)compliance monitoring is included in risk monitoring;
  3. CA-07(04)(c)change monitoring is included in risk monitoring.

Examine

  • Assessment, authorization, and monitoring policy
  • organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • procedures addressing continuous monitoring of system controls
  • assessment report
  • plan of action and milestones
  • system monitoring records
  • impact analyses
  • status reports
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with continuous monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Mechanisms supporting risk monitoring
Official NIST control enhancement

CA-7(5) — Consistency Analysis

Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [Organization-defined: organization-defined actions].

Official discussion

Security and privacy controls are often added incrementally to a system. As a result, policies for selecting and implementing controls may be inconsistent, and the controls could fail to work together in a consistent or coordinated manner. At a minimum, the lack of consistency and coordination could mean that there are unacceptable security and privacy gaps in the system. At worst, it could mean that some of the controls implemented in one location or by one component are actually impeding the functionality of other controls (e.g., encrypting internal network traffic can impede monitoring). In other situations, failing to consistently monitor all implemented network protocols (e.g., a dual stack of IPv4 and IPv6) may create unintended vulnerabilities in the system that could be exploited by adversaries. It is important to validate—through testing, monitoring, and analysis—that the implemented controls are operating in a consistent, coordinated, non-interfering manner.

Organization-defined parameters (3)
organization-defined actions
actionsactions to validate that policies are established are defined;
actionsactions to validate that implemented controls are operating in a consistent manner are defined;
Assessment objectives and methods
  1. CA-07(05)[01][Organization-defined: actions] are employed to validate that policies are established;
  2. CA-07(05)[02][Organization-defined: actions] are employed to validate that implemented controls are operating in a consistent manner.

Examine

  • Assessment, authorization, and monitoring policy
  • organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • procedures addressing continuous monitoring of system security controls
  • assessment report
  • plan of action and milestones
  • system monitoring records
  • security impact analyses
  • status reports
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with continuous monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Mechanisms supporting consistency analyses
Official NIST control enhancement

CA-7(6) — Automation Support for Monitoring

Ensure the accuracy, currency, and availability of monitoring results for the system using [Organization-defined: automated mechanisms].

Official discussion

Using automated tools for monitoring helps to maintain the accuracy, currency, and availability of monitoring information which in turns helps to increase the level of ongoing awareness of the system security and privacy posture in support of organizational risk management decisions.

Organization-defined parameters (1)
automated mechanismsautomated mechanisms used to ensure the accuracy, currency, and availability of monitoring results for the system are defined;
Assessment objectives and methods

[Organization-defined: automated mechanisms] are used to ensure the accuracy, currency, and availability of monitoring results for the system.

Examine

  • Assessment, authorization, and monitoring policy
  • organizational continuous monitoring strategy
  • system-level continuous monitoring strategy
  • procedures addressing continuous monitoring of system controls
  • assessment report
  • plan of action and milestones
  • system monitoring records
  • impact analyses
  • status reports
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with continuous monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Mechanisms supporting automated monitoring
Source record

Authoritative sources