Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring.
| ID | Name | Description | D3FEND | |
| CM0090 | Continuous Monitoring | Maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. | ||
| ID | Description | |
| Requirement | Rationale/Additional Guidance/Notes |
|---|---|
| The [organization] shall monitor, as part of the continuous monitoring strategy, the following: implementation of risk response measures; effectiveness of the risk response implementation; configuration changes that may impact security{CA-7(4)} |
| ID | Name | Description | |
|---|---|---|---|