CA-7—Continuous Monitoring
>Control Description
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:
a. Establishing the following system-level metrics to be monitored: ⚙organization-defined system-level metrics;
b. Establishing ⚙organization-defined frequencies for monitoring and ⚙organization-defined frequencies for assessment of control effectiveness;
c. Ongoing control assessments in accordance with the continuous monitoring strategy;
d. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;
e. Correlation and analysis of information generated by control assessments and monitoring;
f. Response actions to address results of the analysis of control assessment and monitoring information; and
g. Reporting the security and privacy status of the system to ⚙organization-defined personnel or roles ⚙organization-defined frequency.
>Related Controls
Ask AI
Configure your API key to use AI features.