PM-31 Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring
Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored:.
system holds itEvidence a system already holds
- The organisation-wide continuous monitoring strategy document · SIEM / log platform
- Evidence of correlation and analysis of the monitoring data, and the response actions taken · SIEM / log platform
periodic reviewEvidence produced at each review
- The defined organisation-wide metrics to be monitored, and the defined monitoring and assessment frequencies · SIEM / log platform
- Ongoing monitoring and assessment output, showing the metrics were actually produced at the stated frequency · SIEM / log platform
governing documentDocuments that govern the control
- Reporting of the security and privacy status to the defined personnel · Policy repository / GRC workspace
First move
Common gaps auditors find
- Metrics defined but not collected, so the strategy describes monitoring that does not happen
- Data collected without correlation or analysis, producing dashboards nobody acts on
- Frequencies chosen for tool convenience rather than derived from risk, so volatile controls are checked rarely
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-30 Supply Chain Risk Management Strategy. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services; Implement the supply chain risk · PM-32 Purposing. Analyze [organization-defined] supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended purpose