id: "SA-04(08)" title: "Continuous Monitoring Plan for Controls" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.08" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True
Statement
Require the developer of the system, system component, or system service to produce a plan for continuous monitoring of control effectiveness that is consistent with the continuous monitoring program of the organization.
Guidance
The objective of continuous monitoring plans is to determine if the planned, required, and deployed controls within the system, system component, or system service continue to be effective over time based on the inevitable changes that occur. Developer continuous monitoring plans include a sufficient level of detail such that the information can be incorporated into continuous monitoring programs implemented by organizations. Continuous monitoring plans can include the types of control assessment and monitoring activities planned, frequency of control monitoring, and actions to be taken when controls fail or become ineffective.
Assessment Objective
the developer of the system, system component, or system service is required to produce a plan for the continuous monitoring of control effectiveness that is consistent with the continuous monitoring program of the organization.
System and services acquisition policy
procedures addressing developer continuous monitoring plans
procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process
developer continuous monitoring plans
security assessment plans
acquisition contracts for the system, system component, or system service
acquisition documentation
solicitation documentation
service level agreements
system security plan
other relevant documents or records
Organizational personnel with acquisition/contracting responsibilities
organizational personnel with the responsibility for determining system security requirements
system developers
organizational personnel with information security responsibilities
Vendor processes for continuous monitoring
mechanisms supporting and/or implementing developer continuous monitoring