03.12.03: Continuous Monitoring

Control Familly: Security Assessment and Monitoring

SPRS: N/A

Top Ten Failed Requirement: N/A

Supporting Publications:

  • SP 800-37 [59]

  • SP 800-39 [60]

  • SP 800-53A [57]

  • SP 800-115 [58]

  • SP 800-137 [49]

Referenced in: N/A

Control Type: N/A

CPCSC Level 2: 03.12.03

CMMC Level(s): N/A

Derived From: NIST SP 800-53r5

  • CA-07

Develop and implement a system-level continuous monitoring strategy that includes ongoing monitoring and security assessments.

Discussion:

Continuous monitoring at the system level facilitates ongoing awareness of the system security posture to support risk management decisions. The terms continuous and ongoing imply that organizations assess and monitor their systems at a frequency that is sufficient to support risk-based decisions. Different types of security requirements may require different monitoring frequencies.

Assessment Methods and Objectives

Examine [SELECT FROM: security assessment and monitoring policy and procedures; organizational continuous monitoring strategy; system-level continuous monitoring strategy; procedures for continuous monitoring of the system; procedures for configuration management; security assessment report; plan of action and milestones; system monitoring records; configuration management records; impact analyses; status reports; system security plan; other relevant documents or records]

Interview [SELECT FROM: personnel with continuous monitoring responsibilities; personnel with information security responsibilities; system administrators]

Test [SELECT FROM: mechanisms for implementing continuous monitoring; mechanisms for supporting response actions for assessment and monitoring results; mechanisms for supporting security status reporting]

NIST SP 800-171A r3 Determining Statements Determine if:

A.03.12.03[01]: a system-level continuous monitoring strategy is developed.

A.03.12.03[02]: a system-level continuous monitoring strategy is implemented.

A.03.12.03[03]: ongoing monitoring is included in the continuous monitoring strategy.

A.03.12.03[04]: security assessments are included in the continuous monitoring strategy.