3.12 SECURITY ASSESSMENT
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
Continuous monitoring programs facilitate ongoing awareness of threats vulnerabilities and information security to support organizational risk management decisions. The terms continuous and ongoing imply that organizations assess and analyze security controls and information security-related risks at a frequency sufficient to support risk-based decisions. The results of continuous monitoring programs generate appropriate risk response actions by organizations. Providing access to security information on a continuing basis through reports or dashboards gives organizational officials the capability to make effective and timely risk management decisions.Automation supports more frequent updates to hardware software firmware inventories and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific measurable actionable relevant and timely. Monitoring requirements including the need for specific monitoring may also be referenced in other requirements. [SP 800-137] provides guidance on continuous monitoring.
What is a Cybersecurity Compliance Framework?
You don’t need to clutter your security and privacy programs with an ever-increasing number of tools as they become more sophisticated. The Lionfish platform offers a one-stop solution to track progress and monitor any framework, from custom-built ones to highly-specialized and in-demand top security and privacy frameworks and certifications.
With the Lionfish platform, every framework is supported with guided scoping, policies, controls, automated evidence collection, and continuous monitoring, ensuring efficient preparation for audits or attestation in minimal time.
The Lionfish platform is compatible with a wide range of security and privacy frameworks, including:
- CMMC v2
- NERC CIP-002 through CIP-014 Revision 6
- NIST 800-171
- NIST 800-172
- PCI (Payment Card Industry Security Standard)
- SOC 2
- NIST 800-53
- NIST SP800-161 Supply Chain Risk Management
- CIS Framework Controls V8