Continuous Monitoring CA-7
Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CA-7 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CA-7 (Continuous Monitoring) keeps that checkup going instead of once a year. You define a monitoring strategy — which metrics to watch, how often, and who gets the report — then run ongoing control assessments and status monitoring, analyze the results, and respond. It is part of the Moderate baseline.
What good looks like
- Define a monitoring strategy: the metrics to watch and how often to watch them.
- Keep assessing control effectiveness on an ongoing basis, not once a year.
- Monitor the system's security status continuously and correlate what the tools report.
- Report the security status to designated officials on a defined cadence.
- Respond to what the monitoring surfaces — findings feed action.
Framework mapping
- NIST CSF 2.0 — DE.CM-01 — Networks and services are monitored to find potentially adverse events
- CIS Controls v8 — Control 8 — Ongoing audit log collection and review
How to move it toward Implemented
- Real continuous monitoring already runs as services: PlumbWatch, Suricata, Fail2Ban, and
auditdwatch the host live, and unattended-upgrades patches on an ongoing basis. - The gap is that AIDE (Advanced Intrusion Detection Environment) and Lynis are still point-in-time and there is no written strategy — CA-7 wants defined metrics, frequencies, and a named recipient for the status report.
- Schedule AIDE and Lynis to run on a timer (a cron job or systemd timer), then document a one-page monitoring strategy listing what is watched, how often, and who reads the report.
- Attach that strategy plus a sample scheduled-scan output as asset-scoped evidence naming CA-7 to move from partial toward Completed.