Requirements / Security Assessment (CA)
CA.L2-3.12.3
Security Control Monitoring
Official Source Material
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
Determine if:
- [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Ongoing means a defined rhythm faster than your annual assessment.
CA.L2-3.12.1 is the scheduled full assessment. This requirement is the ongoing monitoring between those assessments. Define which controls get checked monthly or quarterly and which ride the annual assessment, and write the rhythm down. You define the frequencies, but a monitoring plan whose every interval is annual has collapsed into CA.L2-3.12.1 and covers neither well. This is also a five-point requirement under 32 CFR 170.24. Its point value bars it from any POA&M, the plan of action and milestones that defers unmet requirements, under 32 CFR 170.21.
Manual monitoring is fine. Undocumented monitoring is invisible.
A recurring ticket that comes due each month is a working continuous monitoring program for a small shop. So is a spreadsheet with the control, the result, the date, and the reviewer's name. The completed records are the entire evidence base for [a]. A dashboard nobody exports and a policy that says monitoring happens both evaporate under the question of when you last did it.
Spend the frequent checks on the volatile controls.
Patching status, vulnerability findings, asset inventory accuracy, account and access reviews, and document drift change weekly. A locked server room does not. Weight the rhythm toward what moves, and let stable controls surface through the annual assessment. Make sure every control appears somewhere in the combined cycle so nothing is monitored by assumption.
Reuse the activities other requirements already force.
Log review, risk assessment under RA.L2-3.11.1, plan of action reviews under CA.L2-3.12.2, and incident response follow-ups are monitoring activities. Reference them in your monitoring plan and route their outputs into it rather than building a parallel program. The guide's chain is direct: monitoring output informs management's risk decisions and keeps the system security plan, the document that says how each requirement is met, honest between assessments.
What falls short
- A policy asserting continuous monitoring with no dated records of any check. Without completed evidence there is nothing showing controls are monitored on an ongoing basis, so [a] is unmet.