CMMC 2.0
Security Assessment

CMMC 2.0 CA.L2-3.12.3: Security Control Monitoring

Monitor security controls continuously so their effectiveness is known on an ongoing basis rather than only at assessment time.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 88 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 12 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 2.2.1 2.2.1 System configuration standards maintained
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

NIST SP 800-53 Rev 5 · 7 controls

CIS Controls v8 · 6 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-18.4 Validate Security Measures
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-8.9 Centralize Audit Logs

SOC 2 · 5 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SEC01-BP03 Identify and validate control objectives
  • SEC01-BP06 Automate deployment of standard security controls
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

HIPAA Security Rule · 3 controls

ISO 22301:2019 · 3 controls

  • 10.1 Nonconformity and corrective action
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2.2 Audit programme(s)

ISO 27001:2022 · 3 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 7.4 Physical security monitoring
  • 8.16 Monitoring activities

NIST SP 800-66 Rev 2 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change

C5 (Germany) · 2 controls

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

FedRAMP High · 2 controls

  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

FedRAMP Moderate · 2 controls

  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

ISO 27002:2022 · 2 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 8.9 Configuration management

ISO 27701:2019 · 2 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.15.2 Information security reviews

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • E8-PATCHOS-ML2 Patch Operating Systems (ML2)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CPS220-P48 Assessment Following Material Change Outside the Review Cycle
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • SPS220-P28 Annual Review in Non Comprehensive Review Years
  • ASD37-28 Continuous incident detection and response (Excellent)
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • AEO-13 Measurement, Analyses and Improvement
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems

ISO/IEC 42001:2023 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-218 · 1 control

  • 53A-F Ongoing Assessment and Automation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security Assessment

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 CA.L2-3.12.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.