id: "SA-04(08)" title: "Continuous Monitoring Plan for Controls" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.08" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True


Statement

Require the developer of the system, system component, or system service to produce a plan for continuous monitoring of control effectiveness that is consistent with the continuous monitoring program of the organization.

Guidance

The objective of continuous monitoring plans is to determine if the planned, required, and deployed controls within the system, system component, or system service continue to be effective over time based on the inevitable changes that occur. Developer continuous monitoring plans include a sufficient level of detail such that the information can be incorporated into continuous monitoring programs implemented by organizations. Continuous monitoring plans can include the types of control assessment and monitoring activities planned, frequency of control monitoring, and actions to be taken when controls fail or become ineffective.

Assessment Objective

the developer of the system, system component, or system service is required to produce a plan for the continuous monitoring of control effectiveness that is consistent with the continuous monitoring program of the organization.

System and services acquisition policy

procedures addressing developer continuous monitoring plans

procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process

developer continuous monitoring plans

security assessment plans

acquisition contracts for the system, system component, or system service

acquisition documentation

solicitation documentation

service level agreements

system security plan

other relevant documents or records

Organizational personnel with acquisition/contracting responsibilities

organizational personnel with the responsibility for determining system security requirements

system developers

organizational personnel with information security responsibilities

Vendor processes for continuous monitoring

mechanisms supporting and/or implementing developer continuous monitoring