GOV-012 Continuous Monitoring Strategy
Description
A continuous monitoring strategy document exists that names the metrics monitored for control effectiveness, the frequency of each and the role accountable for reviewing it. Monitoring outputs are recorded at the stated frequency. Each output showing a control operating outside its expected state is linked to a risk register entry or a remediation record. The strategy names who the deviation is escalated to.
Rationale
A point-in-time audit says nothing about the eleven months between audits, which is where configuration drift, expired certificates and disabled alerts live. The scans, the log aggregation and the posture management sit in INF-007, MON-001 and INF-002. What this control adds is the statement of which of their outputs is a monitoring metric, how often it is read and by whom. GOV-011 is the periodic audit the strategy runs alongside.
Applicability (9 profiles)
Annex point 7.2(b) requires the methods for monitoring, measurement, analysis and evaluation to be determined so as to ensure valid results, which is a statement about method validity rather than about cadence or ownership. Point 7.2 also makes the risk assessment results and past significant incidents inputs to the policy.
Framework Mappings (18)
| A&A-03 | Risk Based Planning Assessment | informative |
| LOG-01 | Logging and Monitoring Policy and Procedures | informative |
| A&A-03 | Risk Based Planning Assessment | informative |
| LOG-01 | Logging and Monitoring Policy and Procedures | informative |
| HIPAA-164.306.e | Maintenance | partial |
| HIPAA-164.316.b.2.iii | Updates | informative |
| NIS2-Art.21.2.f | Assessment of the Effectiveness of Risk-Management Measures | full |
| NIS2-CIR-7 | Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measures | partial |
| CA-7 | Continuous Monitoring | full |
| CA-7(4) | Continuous Monitoring | Risk Monitoring | partial |
| PM-14 | Testing, Training, and Monitoring | partial |
| PM-31 | Continuous Monitoring Strategy | full |
| SI-6 | Security and Privacy Function Verification | partial |
| MG-1.3-002 | High-Priority Risk Response Planning | MG-1.3-002 | full |
| MS-2.7-009 | AI System Security and Resilience Evaluation | MS-2.7-009 | informative |
| CC2.1 | COSO Principle 13: Uses Relevant Information | partial |
| CC4.1 | COSO Principle 16: Conducts Ongoing or Separate Evaluations | partial |
| CC4.2 | COSO Principle 17: Evaluates and Communicates Deficiencies | partial |
Evidence (2)
Continuous monitoring strategy document defining metrics, monitoring frequencies, tool coverage, and responsibilities.
Example: Continuous Monitoring Strategy (Confluence / ISMS document), listing: each monitored control domain, the metric or indicator used, the monitoring frequency, the tool or process performing the check, and the named role responsible for review.
Test: Request the continuous monitoring strategy document. Verify: (1) monitoring frequencies are defined per control domain or metric, (2) responsible roles are named, (3) the strategy has been approved by management and is dated within the last 12 months, (4) the strategy references how monitoring outputs feed into risk register updates.
Continuous monitoring output reports (dashboard, automated scan reports, or metric summaries) generated at the frequencies defined in the strategy.
Example: Security metrics dashboard export (Vanta / Drata / SIEM dashboard PDF) or weekly/monthly monitoring report, showing control health indicators and trend data, timestamped within the defined monitoring interval.
Test: Request monitoring output reports for the last two reporting cycles. Verify: (1) reports are timestamped within the defined frequency, (2) each metric or control indicator in the strategy has a corresponding data point, (3) anomalies or threshold breaches are flagged with a review or response record.
Questions (3)
Does your organisation have a documented continuous monitoring strategy?
The strategy should be documented, management-approved, and reference how monitoring outputs feed into risk register updates, not rely solely on annual audits.
Which of the following continuous monitoring activities are currently operational in your organisation?
Evidence should show monitoring outputs (dashboards, scan reports, alert logs) generated at the frequencies defined in the strategy.
Which of the following does the continuous monitoring strategy record?
Options run from the most commonly recorded to the least. Monitoring that produces output nobody is named to read is the common failure. A deviation with no link onward to a risk entry leaves the strategy reporting problems it never resolves.