PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CA-7 — Continuous Monitoring

Framework: NIST SP 800-53 Rev.5 CA-7 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Obtain the documented system-level Information Security Continuous Monitoring (ISCM) strategy and confirm it defines the monitored metrics, the monitoring/assessment frequency for each, and the reporting cadence to organizational officials.
Examine Confirm the ISCM strategy identifies which specific controls are assessed on an ongoing basis and assigns a defined monitoring frequency to each, rather than deferring all controls to a single point-in-time reassessment.
Test Observe the live monitoring tooling or dashboard (e.g., vulnerability scanner, asset inventory, SIEM) to confirm metrics are actively collected and current, consistent with CIS Controls v8 Safeguards 1 (asset inventory), 7 (continuous vulnerability management), and 8 (audit log management).
Interview Interview security operations personnel to confirm monitoring data is correlated and analyzed, and that defined response actions are triggered when a metric breaches its threshold or a new weakness is detected.
Examine Review the continuous monitoring / security status reports delivered to the Authorizing Official at the defined frequency and confirm they inform ongoing authorization decisions.
Examine Verify that ongoing control assessments actually occurred on schedule and that their results updated the SAR and POA&M (closing remediated items and opening new findings).
Test Confirm automated mechanisms support the monitoring program (per CA-7(6)) by validating that scanner/SIEM/inventory data feeds are integrated and producing current output rather than being maintained manually.