NIST SP 800-171 Rev 3
03.12 CA (Security Assessment and Monitoring)

NIST SP 800-171 Rev 3 03.12.03: Continuous Monitoring

Develop and implement a system-level continuous monitoring strategy that includes ongoing monitoring of security requirements and reporting of security status.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 51 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 3 controls

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

HIPAA Security Rule · 3 controls

  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

NIST SP 800-66 Rev 2 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems
  • CFTC-SS-35 Scope of Testing and Assessment

FedRAMP High · 2 controls

  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

FedRAMP Moderate · 2 controls

  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

PCI DSS 4.0 · 2 controls

  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • E8-PATCHOS-ML2 Patch Operating Systems (ML2)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 1 control

CIS Controls v8 · 1 control

  • CIS-13.1 Centralize Security Event Alerting

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 8.16 Monitoring activities

ISO 27002:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

ISO 27701:2019 · 1 control

  • 5.7.1 Monitoring, measurement, analysis and evaluation

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 53A-F Ongoing Assessment and Automation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.12 CA (Security Assessment and Monitoring)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.12.03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.