NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI)
171A 03.12 Security Assessment and Monitoring

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) 171A-03.12.03: Continuous Monitoring

Determines whether the requirements are monitored on an ongoing basis, so that changes in effectiveness are noticed between formal assessments.

Maintained by Gerard BlokdykVerified against the published standard

What else in your programme already covers this

This control maps to 19 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 3 controls

  • CA-7 Continuous Monitoring
  • CA-7(1) Independent Assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))

FedRAMP Moderate · 3 controls

  • CA-7 Continuous Monitoring
  • CA-7(1) Independent Assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

NIST SP 800-53 Rev 5 · 2 controls

  • ASBv3-GS-5 Define and implement security posture management strategy

CMMC 2.0 · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

ISO 27001:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

SOC 2 · 1 control

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 171A 03.12 Security Assessment and Monitoring

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.