Frameworks / NIST SP 800-53 Rev 5 / NIST800-CA-7 NIST SP 800-53 Rev 5
CA - Assessment, Authorization, and Monitoring
NIST SP 800-53 Rev 5 NIST800-CA-7: CA-7 Continuous Monitoring Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: a. Establishing the following system-level metrics to be monitored: [Assignment: organization-defined system-level metrics]; b. Establishing [Assignment: organization-defined frequencies] for monitoring and [Assignment: organization-defined frequencies] for assessment of control effectiveness; c. Ongoing control assessments in accordance with the continuous monitoring strategy; d. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy; e. Correlation and analysis of information generated by control assessments and monitoring; f. Response actions to address results of the analysis of control assessment and monitoring information; and g. Reporting the security and privacy status of the system to [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 272 controls across 76 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.7 1.2.7 Six-monthly review of NSC configurations 10.4.2 10.4.2 Periodic review of all other system component logs 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 11.1.1 11.1.1 Requirement 11 policies and procedures managed 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.3 11.3.1.3 Internal scans after significant change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.3.4 12.3.4 Annual review of hardware and software technologies 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers 12.8.4 12.8.4 Annual monitoring of TPSP compliance status 2.2.5 2.2.5 Insecure services, protocols or daemons secured 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency 9.4.1.1 9.4.1.1 Secure storage location for offline backups 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 6.5.1 6.5.1 Change control procedure for production 6.5.2 6.5.2 Confirm PCI DSS controls after significant change CIS-1.3 Utilize an Active Discovery Tool CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-13.1 Centralize Security Event Alerting CIS-13.11 Tune Security Event Alerting Thresholds CIS-13.6 Collect Network Traffic Flow Logs CIS-14.7 Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates CIS-15.3 Classify Service Providers CIS-15.6 Monitor Service Providers CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities CIS-17.9 Establish and Maintain Security Incident Thresholds CIS-18.3 Remediate Penetration Test Findings CIS-18.4 Validate Security Measures CIS-2.2 Ensure Authorized Software is Currently Supported CIS-6.8 Define and Maintain Role-Based Access Control CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-8.2 Collect Audit Logs CIS-8.9 Centralize Audit Logs NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-ID.IM-01 Improvements are identified from evaluations NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring AU-6(3) Correlate Audit Record Repositories CA-7 Continuous Monitoring CA-7(1) Independent Assessment CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8 Penetration Testing CM-2(2) Automation Support for Accuracy and Currency CM-8(3) Automated Unauthorized Component Detection IR-4 Incident Handling RA-7 Risk Response SA-2 Allocation of Resources SI-4 System Monitoring SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16)) SI-7(7) Integration of Detection and Response AU-6(3) Correlate Audit Record Repositories CA-7 Continuous Monitoring CA-7(1) Independent Assessment CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CA-8 Penetration Testing CM-2(2) Automation Support for Accuracy and Currency CM-8(3) Automated Unauthorized Component Detection IR-4 Incident Handling SA-2 Allocation of Resources SI-4 System Monitoring SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16)) SI-7(7) Integration of Detection and Response 5.2.4 Information security management system 5.6.2 Information security risk assessment 5.7 Performance evaluation 5.7.1 Monitoring, measurement, analysis and evaluation 5.7.2 Internal audit 5.8 Improvement 5.8.1 Nonconformity and corrective action 5.8.2 Continual improvement 6.12.2 Supplier service delivery management 6.15 Compliance 6.15.2 Information security reviews 6.9.4 Logging and monitoring SOC2-A1.1 A1.1 Managing processing capacity SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2) SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services 5.27 Learning from information security incidents 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.21 Security of network services 8.30 Outsourced development 8.8 Management of technical vulnerabilities CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing CPS230-66 Review of Operational Risk Management CPS230-P23 Senior Management Information to the Board on Resilience Decisions CPS230-P27 Comprehensive Assessment of the Operational Risk Profile CPS230-P30 Monitoring, Review and Testing of Control Effectiveness 29 Para 29 Monitor, review and test controls; report results; rectify gaps promptly 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services 5.25 Assessment and decision on information security events 5.27 Learning from information security incidents 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.16 Monitoring activities 8.8 Management of technical vulnerabilities CPS220-11 Annual Audit Review of the Framework CPS220-16 Management Information System and Data Framework CPS220-18 Triennial Comprehensive Review of the Framework CPS220-P35 Required Content of Risk Management Policies and Procedures CPS220-P47 Minimum Assessment Required by the Framework Review ASBv3-GS-5 Define and implement security posture management strategy ASBv3-LT-1 Enable threat detection capabilities ASBv3-PV-4 Audit and enforce secure configurations for compute resources PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments 10.1 Nonconformity and corrective action 8.5 Exercise programme 9.1 Monitoring, measurement, analysis and evaluation 9.2 Internal audit 9.2.2 Audit programme(s) 8.3 AI risk treatment 9.1 Monitoring, measurement, analysis and evaluation 9.2 Internal audit A.6 AI system life cycle A.6.2.6 AI system operation and monitoring CPS234-22 Systematic Control Testing Program CPS234-P17 Active Maintenance of Capability Against Change CPS234-P30 Independence and Skill of Testing Personnel CPS234-P31 Annual Review of Testing Program Sufficiency ASD37-28 Continuous incident detection and response (Excellent) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ADMF-1.4 Risk management function responsibilities ADMF-6.1 Define monitoring and measurement scope ADMF-6.2 Review controls associated with each category SEC01-BP08 Evaluate and implement new security services and features regularly SEC03-BP04 Reduce permissions continuously SEC04-BP04 Initiate remediation for non-compliant resources C5-COM-04 Information on information security performance and management assessment of the ISMS C5-OPS-10 Logging and Monitoring - Concept C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures API1164-13 Business Continuity and Recovery API1164-20 Program Review and Continuous Improvement SPS220-46 Triennial Comprehensive Review of the Framework SPS220-48 Internal and External Audit Arrangements ACQS-8-3 Continuous Improvement ACQS-CONT-IMPROV Continuous Improvement Plan 3.11.5e Assess Effectiveness of Security Solutions 3.14.2e Monitor Organizational Systems with Specialized Capabilities ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program IRAP-OUT-3 Continuous monitoring and reassessment AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) AEO-13 Measurement, Analyses and Improvement BSI-17 Continuous monitoring strategy CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems ITSG33-RMP-6 Continuous Monitoring STIG-ASSESS-SCAP SCAP automated benchmark scanning DODZT-3.5 Continuous Monitoring and Ongoing Authorizations EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems CAT-D3-2 Detective controls FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722) ICP-24 Macroprudential Surveillance and Insurance Supervision IEC62443-13 Network security monitoring ISO28001-PS-01 Facility Security 27006-9.4 Surveillance and recertification ISO27019-13 Network security monitoring 27400-6.5 Security monitoring and incident response Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures CA-7 CA-7 Continuous Monitoring CA-7 CA-7 Continuous Monitoring CA-7 CA-7 Continuous Monitoring 53A-F Ongoing Assessment and Automation NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NZISM-5 Network Security, System Hardening, and Application Security OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification IM8-SEC.3 Network Security ISMSP-SYS-03 Security Monitoring and Log Management TSAPIPE-2 OT/IT Network Segmentation and Access Control UK-TSA-MON-01 Security Monitoring 3(e) Sec. 3(e) (now 3(c)) Continually verify the cybersecurity of Federal space systems US-SEC-DA-SC-03 ETF Framework Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CA - Assessment, Authorization, and Monitoring You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-CA-7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 272 it maps to, and the evidence behind each claim, over MCP and REST.