CA-7 Continuous Monitoring: Same Assessment, Different Strategy

Two agencies. Same checklist answer: a continuous monitoring program is in place. Both had conducted recent assessments. Both rated CA-7 compliant.

The auditor asked to see the continuous monitoring strategy document.

Agency A pointed to the most recent risk assessment. It was thorough. It identified gaps, assigned risk ratings, and included a remediation plan. The LASO explained that they review their posture annually. The auditor explained that a periodic assessment is not a continuous monitoring strategy. CA-7 requires an ongoing program, not an annual event.

Agency B produced a strategy document: 18 enumerated metrics drawn from the CA-7 metric list, each with a defined monitoring frequency (weekly, monthly, quarterly), a named owner, a collection method (automated, manual, or hybrid), and a review cadence. The most recent monitoring summary showed which metrics were on track, which had findings, and what actions were pending.

The auditor noted Agency A's finding: an annual risk assessment addresses CA-7 in the same way that a quarterly account review addresses AC-2 — it is one point in time, not a continuous program.

What the control actually requires

CA-7 requires the organization to develop a system-level continuous monitoring strategy that includes 20 specific metrics. The strategy must define what is being monitored, how often, by whom, and through what mechanism. It must be implemented — meaning the monitoring must actually occur, not just be described in a document.

The 20 enumerated metrics include controls from AC, AT, AU, CM, IA, IR, MA, PE, SA, SC, and SI. Some of those underlying controls are Priority 2 or higher in the zero cycle. CA-7's monitoring obligation for those metrics applies now even though the underlying control's full implementation deadline has not arrived. The monitoring obligation precedes the implementation deadline.

What the auditor is looking for

A written continuous monitoring strategy naming the metrics, frequencies, owners, and collection methods. Evidence that monitoring is occurring: collection records, metric summaries, review logs. A defined process for acting on findings. Documentation that the strategy has been updated when the environment or the policy changed.

An assessment conducted last quarter is evidence of a past posture. A monitoring program provides a current posture. Those answer different questions.

The common failure mode

Annual assessments were established as the compliance program. They are thorough, well-documented, and conducted by qualified personnel. Nobody recognized that CA-7 requires something different: not a better assessment, but a different model — one where evidence of compliance accumulates continuously rather than being gathered when an audit is approaching.

Read next
Which CJIS 6.1 Requirements Are Sanctionable Today
Priority 1 and existing CJIS requirements have been sanctionable since October 1, 2024. The zero cycle ends September 30, 2027. Two different clocks, cited to policy.

Written by Dr. Alexis W. Perdereaux-Weekes

DBA · CISA · CISM · CRISC · CDPSE

Founder, CJIS360 LLC


Sources: CJIS Security Policy v6.1, 06/25/2026 — CA-7 Continuous Monitoring; §1.4 Terminology Used in This Document. Requirement Companion Document v6.1.

Questions about how this applies to your agency: agency@cjis360.com

Back to the Knowledge Center