NIST SP 800-53 Rev 5
PM - Program Management

NIST SP 800-53 Rev 5 NIST800-PM-31: PM-31 Continuous Monitoring Strategy

Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: a. Establishing the following organization-wide metrics to be monitored: [Assignment: organization-defined metrics]; b. Establishing [Assignment: organization-defined monitoring frequencies] and [Assignment: organization-defined assessment frequencies] for control effectiveness; c. Ongoing monitoring of organizationally-defined metrics in accordance with the continuous monitoring strategy; d. Correlation and analysis of information generated by control assessments and monitoring; e. Response actions to address results of the analysis of control assessment and monitoring information; and f. Reporting the security and privacy status of organizational systems to [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 66 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 8 controls

  • 5.2.4 Information security management system
  • 5.4.2 Information security objectives and planning to achieve them
  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.8 Improvement
  • 5.8.2 Continual improvement
  • 6.15 Compliance
  • 6.15.2 Information security reviews
  • 6.9.4 Logging and monitoring
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

ISO 22301:2019 · 5 controls

  • 10.1 Nonconformity and corrective action
  • 6.1.2 Addressing risks and opportunities
  • 8.5 Exercise programme
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.2.2 Audit programme(s)

ISO 27001:2022 · 5 controls

  • 5.22 Monitoring, review and change management of supplier services
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.16 Monitoring activities
  • 8.8 Management of technical vulnerabilities

SOC 2 · 5 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities

CMMC 2.0 · 4 controls

FedRAMP High · 3 controls

  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • SA-2 Allocation of Resources

FedRAMP Moderate · 3 controls

  • CA-7 Continuous Monitoring
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • SA-2 Allocation of Resources

HIPAA Security Rule · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

  • CPS220-16 Management Information System and Data Framework
  • CPS220-P35 Required Content of Risk Management Policies and Procedures

CIS Controls v8 · 2 controls

  • CIS-15.6 Monitor Service Providers
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 1 control

  • CPS234-22 Systematic Control Testing Program
  • ASBv3-GS-5 Define and implement security posture management strategy

C5 (Germany) · 1 control

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

ISO 27002:2022 · 1 control

  • 8.16 Monitoring activities

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 53A-F Ongoing Assessment and Automation

PCI DSS 4.0 · 1 control

  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PM - Program Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PM-31 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 66 it maps to, and the evidence behind each claim, over MCP and REST.