NIST SP 800-53 Rev 5 MODERATE
CA Assessment, Authorization, and Monitoring

NIST SP 800-53 Rev 5 MODERATE CA-7: Continuous Monitoring

Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.

What else in your programme already covers this

This control maps to 90 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

PCI DSS 4.0 · 7 controls

  • 10.4.3 Exceptions and anomalies addressed
  • 11.2.1 Wireless AP detection
  • 11.4.6 Segmentation testing (service providers) every 6 months
  • 12.10.5 IRP includes monitoring and response to security control alerts
  • 12.4.2 Quarterly PCI compliance reviews (SP)
  • 12.4.2.1 Documentation of quarterly reviews (SP)
  • 5.2.3 Any system components that are not at risk for malware are evaluated periodically to include the following: • A documented list of all system components not at risk for malware. • Identification and evaluation

CIS Controls v8 · 6 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.4 Validate Security Measures
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-8.9 Centralize Audit Logs

ISO 27001:2022 · 6 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.8 Management of technical vulnerabilities
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements
  • CPS230-66 Review of Operational Risk Management
  • CPS230-P23 Senior Management Information to the Board on Resilience Decisions
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-AU-6 Audit record review, analysis, and reporting
  • NIST800-CA-1 Policy and procedures for assessment, authorization, and monitoring
  • NIST800-CA-7 Continuous monitoring
  • NIST800-PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
  • NIST800-SI-4 System monitoring

SOC 2 · 5 controls

  • SOC2-CC2.1 COSO principle 13: Obtains and generates relevant, quality information
  • SOC2-CC3.4 COSO principle 9: Identifies and assesses changes that could impact internal controls
  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts

C5 (Germany) · 4 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

APRA CPS 234 · 3 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

ISO 22301:2019 · 3 controls

  • 10.1 Nonconformity and corrective action
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.3.2 Management review input

ISO 27002:2022 · 3 controls

  • 5.23 Information security for use of cloud services
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems

DORA · 2 controls

  • DORA-Art.10 Detection
  • DORA-Art.24 General requirements for the performance of digital operational resilience testing

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.8.2 Continual improvement

ISO/IEC 42001:2023 · 2 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • A.6.2.6 AI system operation and monitoring

NIST SP 800-66 Rev 2 · 2 controls

  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CBPR-PR-49 Spot checking and monitoring of processors
  • SEC11-BP07 Regularly assess security properties of the pipelines
  • AEO-13 Measurement, Analyses and Improvement

CMMC 2.0 · 1 control

GDPR · 1 control

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 53A-F Ongoing Assessment and Automation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA Assessment, Authorization, and Monitoring

Query this from an agent

The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.