NIST SP 800-53 Rev 5
CA - Assessment, Authorization, and Monitoring

NIST SP 800-53 Rev 5 NIST800-CA-7: CA-7 Continuous Monitoring

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: a. Establishing the following system-level metrics to be monitored: [Assignment: organization-defined system-level metrics]; b. Establishing [Assignment: organization-defined frequencies] for monitoring and [Assignment: organization-defined frequencies] for assessment of control effectiveness; c. Ongoing control assessments in accordance with the continuous monitoring strategy; d. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy; e. Correlation and analysis of information generated by control assessments and monitoring; f. Response actions to address results of the analysis of control assessment and monitoring information; and g. Reporting the security and privacy status of the system to [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 272 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 26 controls

  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 10.4.2 10.4.2 Periodic review of all other system component logs
  • 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis
  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.1 10.7.1 Service providers detect critical control failures (superseded)
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.1.1 11.1.1 Requirement 11 policies and procedures managed
  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change

CIS Controls v8 · 23 controls

  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-13.6 Collect Network Traffic Flow Logs
  • CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
  • CIS-15.3 Classify Service Providers
  • CIS-15.6 Monitor Service Providers
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-17.9 Establish and Maintain Security Incident Thresholds
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-18.4 Validate Security Measures
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-6.8 Define and Maintain Role-Based Access Control
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-8.2 Collect Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.IM-01 Improvements are identified from evaluations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

FedRAMP High · 13 controls

  • AU-6(3) Correlate Audit Record Repositories
  • CA-7 Continuous Monitoring
  • CA-7(1) Independent Assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8 Penetration Testing
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-4 Incident Handling
  • RA-7 Risk Response
  • SA-2 Allocation of Resources
  • SI-4 System Monitoring
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-7(7) Integration of Detection and Response

FedRAMP Moderate · 12 controls

  • AU-6(3) Correlate Audit Record Repositories
  • CA-7 Continuous Monitoring
  • CA-7(1) Independent Assessment
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • CA-8 Penetration Testing
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-8(3) Automated Unauthorized Component Detection
  • IR-4 Incident Handling
  • SA-2 Allocation of Resources
  • SI-4 System Monitoring
  • SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16))
  • SI-7(7) Integration of Detection and Response

ISO 27701:2019 · 12 controls

  • 5.2.4 Information security management system
  • 5.6.2 Information security risk assessment
  • 5.7 Performance evaluation
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.7.2 Internal audit
  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.12.2 Supplier service delivery management
  • 6.15 Compliance
  • 6.15.2 Information security reviews
  • 6.9.4 Logging and monitoring

SOC 2 · 10 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties

ISO 27001:2022 · 9 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.21 Security of network services
  • 8.30 Outsourced development
  • 8.8 Management of technical vulnerabilities
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-66 Review of Operational Risk Management
  • CPS230-P23 Senior Management Information to the Board on Resilience Decisions
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • 29 Para 29 Monitor, review and test controls; report results; rectify gaps promptly

ISO 27002:2022 · 8 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.25 Assessment and decision on information security events
  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.8 Management of technical vulnerabilities

HIPAA Security Rule · 7 controls

NIST SP 800-66 Rev 2 · 6 controls

  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-16 Management Information System and Data Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • CPS220-P47 Minimum Assessment Required by the Framework Review
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

ISO 22301:2019 · 5 controls

  • 10.1 Nonconformity and corrective action
  • 8.5 Exercise programme
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • 9.2.2 Audit programme(s)

ISO/IEC 42001:2023 · 5 controls

  • 8.3 AI risk treatment
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2 Internal audit
  • A.6 AI system life cycle
  • A.6.2.6 AI system operation and monitoring

APRA CPS 234 · 4 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P31 Annual Review of Testing Program Sufficiency
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)
  • ADMF-1.4 Risk management function responsibilities
  • ADMF-6.1 Define monitoring and measurement scope
  • ADMF-6.2 Review controls associated with each category
  • SEC01-BP08 Evaluate and implement new security services and features regularly
  • SEC03-BP04 Reduce permissions continuously
  • SEC04-BP04 Initiate remediation for non-compliant resources

C5 (Germany) · 3 controls

  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

API 1164 · 2 controls

  • API1164-13 Business Continuity and Recovery
  • API1164-20 Program Review and Continuous Improvement
  • SPS220-46 Triennial Comprehensive Review of the Framework
  • SPS220-48 Internal and External Audit Arrangements
  • ACQS-8-3 Continuous Improvement
  • ACQS-CONT-IMPROV Continuous Improvement Plan

CMMC 2.0 · 2 controls

NIST SP 800-160 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities

NIST SP 800-207 · 2 controls

  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • IRAP-OUT-3 Continuous monitoring and reassessment
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • AEO-13 Measurement, Analyses and Improvement

BSI IT-Grundschutz · 1 control

  • BSI-17 Continuous monitoring strategy
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems
  • ITSG33-RMP-6 Continuous Monitoring
  • STIG-ASSESS-SCAP SCAP automated benchmark scanning

DORA · 1 control

  • DODZT-3.5 Continuous Monitoring and Ongoing Authorizations

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
  • CAT-D3-2 Detective controls
  • FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)
  • ICP-24 Macroprudential Surveillance and Insurance Supervision

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring
  • ISO28001-PS-01 Facility Security
  • 27006-9.4 Surveillance and recertification

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 1800-32 · 1 control

NIST SP 800-128 · 1 control

NIST SP 800-171 · 1 control

NIST SP 800-187 · 1 control

NIST SP 800-190 · 1 control

  • CA-7 CA-7 Continuous Monitoring
  • CA-7 CA-7 Continuous Monitoring
  • CA-7 CA-7 Continuous Monitoring
  • 53A-F Ongoing Assessment and Automation
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • NZISM-5 Network Security, System Hardening, and Application Security
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

South Korea ISMS-P · 1 control

  • ISMSP-SYS-03 Security Monitoring and Log Management
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UK-TSA-MON-01 Security Monitoring
  • 3(e) Sec. 3(e) (now 3(c)) Continually verify the cybersecurity of Federal space systems
  • US-SEC-DA-SC-03 ETF Framework

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA - Assessment, Authorization, and Monitoring

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CA-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 272 it maps to, and the evidence behind each claim, over MCP and REST.