Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family CA

CA-7Continuous Monitoring

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: Establishing the following system-level metrics to be monitored: {{ insert: param, ca-07_odp.01 }}; Establishing {{ insert: param, ca-07_odp.02 }} for monitoring and {{ insert: param, ca-07_odp.03 }} for assessment of control effectiveness; Ongoing control assessments in accordance with the continuous monitoring strategy; Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy; Correlation and analysis of information generated by control assessments and monitoring; Response actions to address results of the analysis of control assessment and monitoring information; and Reporting the security and privacy status of the system to {{ insert: param, ca-7_prm_4 }} {{ insert: param, ca-7_prm_5 }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (208)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-693Protection Mechanism Failure476Ongoing control assessments and analysis of monitoring data enable timely detection and response when protection mechanisms fail.
CWE-703Improper Check or Handling of Exceptional Conditions146Establishing and monitoring system metrics with correlation and response actions helps identify and address improper handling of exceptional conditions.
CWE-778Insufficient Logging23Continuous monitoring requires establishing metrics, ongoing data collection, correlation, and analysis, directly mitigating insufficient logging by ensuring security-relevant events are captured and reviewed.
CWE-390Detection of Error Condition Without Action14The control mandates response actions to address results from monitoring and assessments, preventing detection of error conditions without subsequent corrective action.
CWE-392Missing Report of Error Condition11Reporting the security and privacy status to organizational officials ensures monitoring and assessment results are communicated rather than omitted.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family CA

CA-1 CA-2 CA-3 CA-4 CA-5 CA-6 CA-8 CA-9