Under active development Content is continuously updated and improved

SA-4(8)Acquisition Process

Management

>Control Description

ACQUISITION PROCESS | CONTINUOUS MONITORING PLAN The organization requires the developer of the information system, system component, or information system service to produce a plan for the continuous monitoring of security control effectiveness that contains organization-defined level of detail.

>Supplemental Guidance

The objective of continuous monitoring plans is to determine if the complete set of planned, required, and deployed security controls within the information system, system component, or information system service continue to be effective over time based on the inevitable changes that occur. Developer continuous monitoring plans include a sufficient level of detail such that the information can be incorporated into the continuous monitoring strategies and programs implemented by organizations. Related control: CA-7.

Ask AI

Configure your API key to use AI features.