Frameworks / FedRAMP High / CA-7 FedRAMP High
CA - Assessment, Authorization, and Monitoring
FedRAMP High CA-7: Continuous Monitoring Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.
What else in your programme already covers this This control maps to 90 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring 10.4.3 Exceptions and anomalies addressed 11.2.1 Wireless AP detection 11.4.6 Segmentation testing (service providers) every 6 months 12.10.5 IRP includes monitoring and response to security control alerts 12.4.2 Quarterly PCI compliance reviews (SP) 12.4.2.1 Documentation of quarterly reviews (SP) 5.2.3 Any system components that are not at risk for malware are evaluated periodically to include the following: • A documented list of all system components not at risk for malware. • Identification and evaluation CIS-13.1 Centralize Security Event Alerting CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.4 Validate Security Measures CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-8.9 Centralize Audit Logs 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.8 Management of technical vulnerabilities CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements CPS230-66 Review of Operational Risk Management CPS230-P23 Senior Management Information to the Board on Resilience Decisions CPS230-P27 Comprehensive Assessment of the Operational Risk Profile CPS230-P30 Monitoring, Review and Testing of Control Effectiveness NIST800-AU-6 Audit record review, analysis, and reporting NIST800-CA-1 Policy and procedures for assessment, authorization, and monitoring NIST800-CA-7 Continuous monitoring NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring NIST800-SI-4 System monitoring SOC2-CC2.1 COSO principle 13: Obtains and generates relevant, quality information SOC2-CC3.4 COSO principle 9: Identifies and assesses changes that could impact internal controls SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations SOC2-CC7.1 Detection and monitoring procedures for security events are in place SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts C5-COM-03 Internal audits of the information security management system C5-COM-04 Information on information security performance and management assessment of the ISMS C5-OPS-10 Logging and Monitoring - Concept C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures CPS234-22 Systematic Control Testing Program CPS234-P17 Active Maintenance of Capability Against Change CPS234-P31 Annual Review of Testing Program Sufficiency ASBv3-PV-4 Audit and enforce secure configurations for compute resources PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments 10.1 Nonconformity and corrective action 9.1 Monitoring, measurement, analysis and evaluation 9.3.2 Management review input 5.23 Information security for use of cloud services 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems DORA-Art.10 Detection DORA-Art.24 General requirements for the performance of digital operational resilience testing 5.7.1 Monitoring, measurement, analysis and evaluation 5.8.2 Continual improvement 9.1 Monitoring, measurement, analysis and evaluation A.6.2.6 AI system operation and monitoring ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions CBPR-PR-49 Spot checking and monitoring of processors SEC11-BP07 Regularly assess security properties of the pipelines AEO-13 Measurement, Analyses and Improvement Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures 3.11.5e Assess Effectiveness of Security Solutions 53A-F Ongoing Assessment and Automation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CA - Assessment, Authorization, and Monitoring You are reading one control. How much of FedRAMP High have you already done? FedRAMP High CA-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP High your existing evidence covers. Hold C5 (Germany) and 119 of 410 FedRAMP High controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 6 were rejected on the C5 (Germany) pair alone.
Query this from an agent The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.