Skip to content

CA-7: Continuous Monitoring

An OSCAL Control

Statement

    • Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:

      • a.

        Establishing the following system-level metrics to be monitored: ;

      • b.

        Establishing for monitoring and for assessment of control effectiveness;

      • c.

        Ongoing control assessments in accordance with the continuous monitoring strategy;

      • d.

        Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;

      • e.

        Correlation and analysis of information generated by control assessments and monitoring;

      • f.

        Response actions to address results of the analysis of control assessment and monitoring information; and

      • g.

        Reporting the security and privacy status of the system to .