800-53|CA-7

Title

CONTINUOUS MONITORING

Description

The organization develops a continuous monitoring strategy and implements a continuous monitoring program that includes:

Supplemental

Continuous monitoring programs facilitate ongoing awareness of threats, vulnerabilities, and information security to support organizational risk management decisions. The terms continuous and ongoing imply that organizations assess/analyze security controls and information security-related risks at a frequency sufficient to support organizational risk-based decisions. The results of continuous monitoring programs generate appropriate risk response actions by organizations. Continuous monitoring programs also allow organizations to maintain the security authorizations of information systems and common controls over time in highly dynamic environments of operation with changing mission/business needs, threats, vulnerabilities, and technologies. Having access to security-related information on a continuing basis through reports/dashboards gives organizational officials the capability to make more effective and timely risk management decisions, including ongoing security authorization decisions. Automation supports more frequent updates to security authorization packages, hardware/software/firmware inventories, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of information systems.

Reference Item Details

Related: CA-2,CA-5,CA-6,CM-3,CM-4,PM-6,PM-9,RA-5,SA-11,SA-12,SI-2,SI-4

Category: SECURITY ASSESSMENT AND AUTHORIZATION

Family: SECURITY ASSESSMENT AND AUTHORIZATION

Priority: P2

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMAirWatch - CIS Apple iPadOS 17 v1.1.0 End User Owned L1
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMAirWatch - CIS Apple iPadOS 18 v1.0.0 L1 End User Owned
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMMobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMAirWatch - CIS Apple iOS 17 Benchmark v1.1.0 End User Owned L1
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMMobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMAirWatch - CIS Apple iOS 18 Benchmark v1.0.0 L1 End User Owned
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMMobileIron - CIS Apple iOS 18 v1.0.0 L1 End User Owned
4.8 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end user-owned devicesMDMMobileIron - CIS Apple iPadOS 18 v1.0.0 L1 End User Owned
5.3.21 Ensure SSH AllowTcpForwarding is disabledUnixCIS Ubuntu Linux 16.04 LTS Server L2 v2.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabledUnixCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshdUnixCIS Red Hat 6 Server L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshdUnixCIS CentOS 6 Workstation L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshdUnixCIS Red Hat 6 Workstation L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshdUnixCIS CentOS 6 Server L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshdUnixCIS Oracle Linux 6 Server L2 v2.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshdUnixCIS Oracle Linux 6 Workstation L2 v2.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshd_configUnixCIS Red Hat 6 Server L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshd_configUnixCIS CentOS 6 Server L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshd_configUnixCIS CentOS 6 Workstation L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshd_configUnixCIS Red Hat 6 Workstation L2 v3.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshd_configUnixCIS Oracle Linux 6 Server L2 v2.0.0
5.3.21 Ensure SSH AllowTcpForwarding is disabled - sshd_configUnixCIS Oracle Linux 6 Workstation L2 v2.0.0
6.15 Ensure a secure Data Filtering profile is applied to all security policies allowing traffic to or from the InternetPalo_AltoCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0