1Overview
CA.L2-3.12.3 is the family's second five-point requirement and it makes control oversight continuous. It requires that security controls be monitored on an ongoing basis to ensure their continued effectiveness, so that controls are watched between assessments rather than only checked at intervals. It is a five-point requirement that cannot be deferred on a plan of action.
Periodic assessment verifies controls at points in time, but effectiveness can lapse between those points, as configurations drift, systems change, and controls quietly stop working. This control requires ongoing monitoring of security controls to ensure their continued effectiveness, so the program has continuous awareness of whether its controls are still doing their job. It complements the periodic assessment of the family's first control by covering the intervals between assessments. Its five-point weight reflects that a control that lapses unnoticed is as good as absent until the next check.
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
The requirement is ongoing monitoring of security controls for continued effectiveness. In practice this means continuous or frequent oversight, often through automated monitoring, alerting, and review, that surfaces when a control is failing or has drifted rather than waiting for a scheduled assessment. The single assessment objective is that controls are monitored on an ongoing basis to ensure they remain effective.
2The Assessment Objective
NIST SP 800-171A frames 3.12.3 as a single objective: monitor controls on an ongoing basis for continued effectiveness.
Security controls are monitored on an ongoing basis to ensure the continued effectiveness of the controls. Controls are watched continuously, not only at intervals.
The single objective is ongoing monitoring for continued effectiveness. The common failure is relying solely on periodic assessment, so a control that lapses between checks goes unnoticed. The assessor looks for continuous or frequent monitoring that surfaces control failures as they occur.
3Failure Patterns
The failures are about controls watched only at intervals.
Point-in-time checks only
Relying only on periodic assessment leaves the intervals between unmonitored, so a control that fails after an assessment goes unnoticed until the next one. Ongoing monitoring covers those intervals.
Monitoring not reviewed
Monitoring that generates data or alerts no one reviews does not surface lapses. The monitoring has to be acted on to ensure continued effectiveness.
Partial coverage
Monitoring some controls while leaving others watched only at assessment leaves gaps. Ongoing monitoring should cover the controls whose continued effectiveness matters.
4Ownership
This is a security and IT-owned control tied to continuous monitoring.
| Role | Responsibility for this control |
|---|---|
| IT and security | Monitors security controls on an ongoing basis and responds to lapses. Owns the monitoring evidence. |
| Security or compliance lead | Confirms monitoring covers the relevant controls and is acted on. |
| Program lead | Reviews monitoring output and retains the records. |
5Tooling
The control is delivered by continuous or frequent monitoring of control effectiveness.
| Objective | Tooling | What it provides |
|---|---|---|
| monitor | Automated monitoring and alerting | Ongoing awareness of control status. |
| respond | Review and response to monitoring | Action on lapses to ensure continued effectiveness. |
The caveat is that monitoring has to be ongoing and acted on, covering the controls that matter. Monitoring data no one reviews, or coverage limited to a few controls, does not ensure continued effectiveness. The assessor examines whether controls are monitored on an ongoing basis, so the monitoring has to be continuous and responsive.
6Evidence
The satisfied version of 3.12.3 shows controls monitored continuously.
| Evidence | What it demonstrates |
|---|---|
| Monitoring configuration | The objective. Controls monitored on an ongoing basis. |
| Monitoring review and response records | The objective. Lapses surfaced and acted on. |
The evidence should show security controls monitored on an ongoing basis and the monitoring reviewed and acted on. The monitoring configuration together with the review records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
Between assessments, a lapsed control is a blind spot
Controls drift and fail between periodic checks, so this five-point control asks for ongoing monitoring that surfaces lapses as they happen. Building continuous control monitoring that is actually reviewed is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.12.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.12.3. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing CA.L2-3.12.3 among the five-point basic security requirements. ecfr.gov