← Controls / CA

CA-07 Continuous Monitoring

Security Assessment and Authorization

Low Moderate High Privacy

Description

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: a. Establishing the following system-level metrics to be monitored: [Assignment: organization-defined system-level metrics]; b. Establishing [Assignment: organization-defined frequencies] for monitoring and [Assignment: organization-defined frequencies] for assessment of control effectiveness; c. Ongoing control assessments in accordance with the continuous monitoring strategy; d. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy; e. Correlation and analysis of information generated by control assessments and monitoring; f. Response actions to address results of the analysis of control assessment and monitoring information; and g. Reporting the security and privacy status of the system to [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency].

Supplemental Guidance

Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions. Automation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as AC-02g, AC-02(07), AC-02(12)(a), AC-02(07)(b), AC-02(07)(c), AC-17(01), AT-04a, AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, CM-11c, IR-05, MA-02b, MA-03a, MA-04a, PE-03d, PE-06, PE-14b, PE-16, PE-20, PM-06, PM-23, PM-31, PS-07e, SA-09c, SR-04, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b, and SI-04.

Changes from Rev 4

Control text changes 'metrics' to 'system-level metrics' Parameter changes 'metrics' to 'system-level metrics' Discussion expanded

Enhancements (5)

What NIST adds to this control. Select one to read its statement.

CA-07(01) Independent Assessment ModerateHigh

Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.

CA-07(03) Trend Analyses

Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in the continuous monitoring process need to be modified based on empirical data.

CA-07(04) Risk Monitoring LowModerateHighPrivacy

Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: a. Effectiveness monitoring; b. Compliance monitoring; and c. Change monitoring.

CA-07(05) Consistency Analysis

Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [Assignment: organization-defined actions].

CA-07(06) Automation Support for Monitoring

Ensure the accuracy, currency, and availability of monitoring results for the system using [Assignment: organization-defined automated mechanisms].

Withdrawn by NIST:

  • CA-07(02) Types of Assessments, now in CA-02

MITRE ATT&CK Techniques (210)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Reconnaissance 4 Initial Access 13 Execution 13 Persistence 33 Privilege Escalation 30 Defense Evasion 57 Credential Access 40 Discovery 3 Lateral Movement 8 Collection 17 Command & Control 34 Exfiltration 11 Impact 12
Show all 210 techniques grouped by tactic

Persistence

Privilege Escalation

Defense Evasion

T1036 T1070 T1078 T1197 T1205 T1211 T1218 T1221 T1222 T1548 T1556 T1562 T1574 T1599 T1622 T1647 T1036.003 T1036.005 T1036.007 T1055.009 T1070.001 T1070.002 T1070.003 T1070.007 T1070.008 T1070.009 T1078.001 T1078.003 T1078.004 T1205.001 T1218.002 T1218.010 T1218.011 T1218.012 T1218.015 T1222.001 T1222.002 T1542.004 T1542.005 T1548.003 T1548.006 T1550.003 T1553.003 T1556.001 T1562.001 T1562.002 T1562.004 T1562.006 T1564.004 T1564.010 T1574.004 T1574.007 T1574.008 T1574.009 T1574.013 T1574.014 T1599.001

Credential Access

Command & Control

Compliance Mappings

ISO 27001:2022

9.19.29.310.1A.5.22A.5.35A.5.36A.8.16

ISO 27002:2022

5.225.355.368.16

COBIT 2019

APO13DSS01MEA01MEA02MEA04

CIS Controls v8

CIS 7CIS 13CIS 15.6

NIST CSF 2.0

DE.AE-02DE.AE-03DE.CM-01DE.CM-02DE.CM-03DE.CM-06DE.CM-09GV.OV-01GV.OV-03GV.PO-02ID.IM-01ID.IM-02ID.IM-03ID.RA-01ID.RA-07PR.PS-04RC.RP-05

SOC 2 TSC

CC1.1CC1.1-POF3CC2.2CC2.3CC4.2-POF1CC4.2-POF2

PCI DSS v4.0.1

12.4

CSA CCM v4

AA-02AIS-03LOG-03LOG-10SEF-05STA-11TVM-09TVM-10

CSA AICM v1

A&A-02AIS-03AIS-12GRC-12GRC-15LOG-03LOG-10LOG-15MDS-05SEF-05STA-11TVM-09TVM-10TVM-13

FINOS CCC

CCC-C08

ISO 42001:2023

A.2.4A.6.2.6

IEC 62443

3-3 SR 6.2

NIS2 Directive

Art. 21(2)(f)Art. 32

PRA Operational Resilience

SS1/21-7.1SS2/21-7.1

MAS TRM

712

BSI IT-Grundschutz

DER.1

ANSSI

Hygiene.3Hygiene.29Hygiene.31Hygiene.39SecNumCloud.13.7SecNumCloud.19.2

FINMA Circular 2023/1

IV.C(66)IV.C(67)IV.C(68)IV.D(75)IV.D(76)

OSFI B-13

B-13.1.3B-13.3.3B-13.4.2

EU GDPR

Art.32(1)(d)Art.35(11)

EU DORA

Art.6(4)Art.10(1)Art.10(2)Art.24(1)

BIO2

5.225.355.368.16

RBI CSF

Annex1.21ITGRCA.21ITGRCA.30

FISC Security Guidelines

FISC.O2FISC.O7

LGPD + BCB 4893

BCB.Art.6BCB.Art.10BCB.Art.19LGPD.Art.50

HKMA TM-E-1

TME1.2.6TME1.5.2TME1.12.3

MLPS 2.0

8.1.5.38.1.7.28.1.9.6

DNB Good Practice

DNB.14.1DNB.16.1DNB.16.2

SAMA CSF

1.31.92.2

NCA ECC

1-71-82-125-1

UAE IA

T7

CBB TM

TM-5TM-12TM-16

Qatar NIA

GVOSRM

CBUAE

CR-3CR-10CR-14

CBE CSF

CD-1GOV-3OVM-3

SA JS2

JS2-7.3JS2-7.6JS2-7.7JS2-9

CBN CSF

Part2.2Part2.3Part3.5Part6.1Part6.2Part7.2

BoG CISD

CISD-COMPCISD-IICISD-IIICISD-ISMSCISD-IVCISD-VII

POPIA

s19

BoM CTRM

1.53.14.25.35.4

IOSCO Cyber Resilience

DET-1DET-2LE-1LE-2SA-3TEST-1

BCBS 239

Principle 7Principle 8Principle 10Principle 12

CPMI-IOSCO PFMI

CG.DECG.LEPFMI.P3PFMI.P17

FFIEC IS

II.AII.A.2II.C.4II.DIII.AIII.BIV.AIV.A.3

NYDFS 500

500.2

HIPAA Security Rule

§164.308(a)(1)(i)§164.308(a)(1)(ii)(A)§164.308(a)(1)(ii)(B)§164.308(a)(1)(ii)(D)§164.308(a)(7)(ii)(D)§164.308(a)(8)§164.316(b)(2)(iii)

ECB CROE

CROE.2.2.1CROE.2.4CROE.2.8.1

EBA ICT Guidelines

3.3.53.3.63.4.53.4.6

SEBI CSCRF

AUDITCCIDE.CMGV.OVRS.IMSOC

BOT Cyber Resilience

Ch1.3Ch3.1Ch6.1Ch10.1

CMMC 2.0

CA

NERC CIP

CIP-015-1

10 CFR 73.54

73.54(d)RG5.71-C-CA

TSA Pipeline SD

SD-2 Sec C

FERC CIP Orders

Order 881Order 893

DOE C2M2 v2.1

SITUATION

API 1164

Sec 9Sec 15

AWIA

AWWA Sec 4AWWA Sec 5

IAEA NSS 17-T

Sec 5.5Sec 11

CBEST

CBEST.5CBEST.7CBEST.10

TIBER-EU

TIBER.BTTIBER.REM

PCI HSM

10

Common Criteria

CEM

ISAE 3402

Clause 2Clause 5Clause 6Clause 10

Solvency II

Art.45Art.46Art.47EIOPA-ICT-4.2

Lloyd's Minimum Standards

MS8.12MS10.2

NAIC Insurance Data Security

44-monitoring4A4E57

PRA SS1/23

P4.1P5.2

FCA SYSC 13

SYSC 13.5.3SYSC 13.7.5SYSC 13.9.3SYSC 13.G.3

HITRUST CSF v11

00.b00.c03.b04.b06.c11.b12.c

FDA 21 CFR Part 11

§11.10(a)

FDA Cybersecurity Guidance

524B-2524B-4

ISO 27799

5.218.3

NHS DSPT

NDG-5.1NDG-7.3NDG-9.9

CCSS v9.0

2.01.12.01.3

MiCA

Art.34(5)Art.43(1)Art.62(1)Art.94(1)

Basel SCO60

SCO60.5SCO60.13SCO60.23SCO60.50SCO60.51SCO60.65SCO60.71SCO60.72SCO60.73SCO60.74

BSSC Standards

GSP-15NOS-10

SEC Custody (Digital Assets)

SEC-CD-10SEC-CD-13SEC-CD-14

India DPDPA

Act.8(4)Act.10(2)(c)Rules.6(1)(g)Rules.13(1)-(2)Rules.Sch1.B.12

ISO 17799 (legacy)

15.2.115.2.2

COBIT 4.1 (legacy)

PO1.3DS5.5