CA-7 Continuous monitoring
Requires a system-level continuous monitoring strategy aligned to the organizational one, defining the metrics monitored, the frequencies for monitoring and for assessing control effectiveness, ongoing control assessment
4
artefacts
2
held by a system
1
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Documented continuous monitoring strategy with metrics and frequencies · SIEM / log platform
- Correlation and analysis output showing findings drawn from monitoring data · SIEM / log platform
periodic reviewEvidence produced at each review
- Evidence of ongoing control assessments performed at the stated cadence · Document repository
governing documentDocuments that govern the control
- Posture reports issued to the defined personnel and the actions they triggered · Document repository
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- Monitoring reduced to vulnerability scanning, with most controls never reassessed
- Metrics defined but never collected or reported
- Findings analysed in isolation rather than correlated across sources
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet