Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >SP 800-53
  3. >Assessment, Authorization, And Monitoring
  4. >SP800-53-CA-7
SP800-53-CA-7Active

Continuous Monitoring

Statement

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: Establishing the following system-level metrics to be monitored: system-level metrics; Establishing frequencies for monitoring and frequencies for assessment of control effectiveness; Ongoing control assessments in accordance with the continuous monitoring strategy; Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy; Correlation and analysis of information generated by control assessments and monitoring; Response actions to address results of the analysis of control assessment and monitoring information; and Reporting the security and privacy status of the system to system-level metrics; frequencies; personnel or roles; frequency system-level metrics; frequencies; personnel or roles; frequency.

Location

Control Family
Assessment, Authorization, and Monitoring

Control Details

Identifier
SP800-53-CA-7
Family
CA

Organisation-Defined Parameters

ca-07_odp.01
system-level metrics
ca-07_odp.02
frequencies
ca-07_odp.03
frequencies
ca-07_odp.04
personnel or roles
ca-07_odp.05
frequency
ca-07_odp.06
personnel or roles
ca-07_odp.07
frequency

Supplemental Guidance

Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms "continuous" and "ongoing" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions.

Automation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as AC-2g, AC-2(7), AC-2(12)(a), AC-2(7)(b), AC-2(7)(c), AC-17(1), AT-4a, AU-13, AU-13(1), AU-13(2), CM-3f, CM-6d, CM-11c, IR-5, MA-2b, MA-3a, MA-4a, PE-3d, PE-6, PE-14b, PE-16, PE-20, PM-6, PM-23, PM-31, PS-7e, SA-9c, SR-4, SC-5(3)(b), SC-7a, SC-7(24)(b), SC-18b, SC-43b , and SI-4.

Assessment Objective

a system-level continuous monitoring strategy is developed; system-level continuous monitoring is implemented in accordance with the organization-level continuous monitoring strategy; system-level continuous monitoring includes establishment of the following system-level metrics to be monitored: system-level metrics; system-level continuous monitoring includes established frequencies for monitoring; system-level continuous monitoring includes established frequencies for assessment of control effectiveness; system-level continuous monitoring includes ongoing control assessments in accordance with the continuous monitoring strategy; system-level continuous monitoring includes ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy; system-level continuous monitoring includes correlation and analysis of information generated by control assessments and monitoring; system-level continuous monitoring includes response actions to address the results of the analysis of control assessment and monitoring information; system-level continuous monitoring includes reporting the security status of the system to personnel or roles frequency; system-level continuous monitoring includes reporting the privacy status of the system to personnel or roles frequency.

ATTACK
ATTACK-T1037.002relatedvia ctid-attack-to-sp800-53
ATTACK-T1037.005relatedvia ctid-attack-to-sp800-53
ATTACK-T1059relatedvia ctid-attack-to-sp800-53
ATTACK-T1059.005relatedvia ctid-attack-to-sp800-53
ATTACK-T1070relatedvia ctid-attack-to-sp800-53
View in graphReport an issue
← Back to Assessment, Authorization, and Monitoring
Assessment, Authorization, and Monitoring32 controls
SP800-53-CA-1Policy and ProceduresSP800-53-CA-2Control AssessmentsSP800-53-CA-2(1)Independent AssessorsSP800-53-CA-2(2)Specialized AssessmentsSP800-53-CA-2(3)Leveraging Results from External OrganizationsSP800-53-CA-3Information ExchangeSP800-53-CA-3(1)Unclassified National Security System ConnectionsSP800-53-CA-3(2)Classified National Security System ConnectionsSP800-53-CA-3(3)Unclassified Non-national Security System ConnectionsSP800-53-CA-3(4)Connections to Public NetworksSP800-53-CA-3(5)Restrictions on External System ConnectionsSP800-53-CA-3(6)Transfer AuthorizationsSP800-53-CA-3(7)Transitive Information ExchangesSP800-53-CA-4Security CertificationSP800-53-CA-5Plan of Action and MilestonesSP800-53-CA-5(1)Automation Support for Accuracy and CurrencySP800-53-CA-6AuthorizationSP800-53-CA-6(1)Joint Authorization — Intra-organizationSP800-53-CA-6(2)Joint Authorization — Inter-organizationSP800-53-CA-7Continuous MonitoringSP800-53-CA-7(1)Independent AssessmentSP800-53-CA-7(2)Types of AssessmentsSP800-53-CA-7(3)Trend AnalysesSP800-53-CA-7(4)Risk MonitoringSP800-53-CA-7(5)Consistency AnalysisSP800-53-CA-7(6)Automation Support for MonitoringSP800-53-CA-8Penetration TestingSP800-53-CA-8(1)Independent Penetration Testing Agent or TeamSP800-53-CA-8(2)Red Team ExercisesSP800-53-CA-8(3)Facility Penetration TestingSP800-53-CA-9Internal System ConnectionsSP800-53-CA-9(1)Compliance Checks