Frameworks / FedRAMP Moderate / CA-7 FedRAMP Moderate
CA - Assessment, Authorization, and Monitoring
FedRAMP Moderate CA-7: Continuous Monitoring Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 93 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.4.6 11.4.6 Service provider segmentation testing every six months 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware CIS-13.1 Centralize Security Event Alerting CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.4 Validate Security Measures CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-8.9 Centralize Audit Logs 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.8 Management of technical vulnerabilities CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements CPS230-66 Review of Operational Risk Management CPS230-P23 Senior Management Information to the Board on Resilience Decisions CPS230-P27 Comprehensive Assessment of the Operational Risk Profile CPS230-P30 Monitoring, Review and Testing of Control Effectiveness SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies C5-COM-03 Internal audits of the information security management system C5-COM-04 Information on information security performance and management assessment of the ISMS C5-OPS-10 Logging and Monitoring - Concept C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures CPS234-22 Systematic Control Testing Program CPS234-P17 Active Maintenance of Capability Against Change CPS234-P31 Annual Review of Testing Program Sufficiency ASBv3-PV-4 Audit and enforce secure configurations for compute resources PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments 10.1 Nonconformity and corrective action 9.1 Monitoring, measurement, analysis and evaluation 9.3.2 Management review input 5.23 Information security for use of cloud services 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems DORA-Art.10 Detection DORA-Art.24 General requirements for the performance of digital operational resilience testing 5.7.1 Monitoring, measurement, analysis and evaluation 5.8.2 Continual improvement 9.1 Monitoring, measurement, analysis and evaluation A.6.2.6 AI system operation and monitoring ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions CBPR-PR-49 Spot checking and monitoring of processors SEC11-BP07 Regularly assess security properties of the pipelines AEO-13 Measurement, Analyses and Improvement Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures 3.11.5e Assess Effectiveness of Security Solutions CA-7 CA-7 Continuous Monitoring CA-7 CA-7 Continuous Monitoring CA-7 CA-7 Continuous Monitoring 53A-F Ongoing Assessment and Automation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CA - Assessment, Authorization, and Monitoring You are reading one control. How much of FedRAMP Moderate have you already done? FedRAMP Moderate CA-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of FedRAMP Moderate your existing evidence covers. Hold ISO 27002:2022 and 182 of 323 FedRAMP Moderate controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 348 were rejected on the ISO 27002:2022 pair alone.
Query this from an agent The graph holds this control, the 93 it maps to, and the evidence behind each claim, over MCP and REST.