GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-012 Continuous Monitoring Strategy

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A continuous monitoring strategy document exists that names the metrics monitored for control effectiveness, the frequency of each and the role accountable for reviewing it. Monitoring outputs are recorded at the stated frequency. Each output showing a control operating outside its expected state is linked to a risk register entry or a remediation record. The strategy names who the deviation is escalated to.

Rationale

A point-in-time audit says nothing about the eleven months between audits, which is where configuration drift, expired certificates and disabled alerts live. The scans, the log aggregation and the posture management sit in INF-007, MON-001 and INF-002. What this control adds is the statement of which of their outputs is a monitoring metric, how often it is read and by whom. GOV-011 is the periodic audit the strategy runs alongside.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex point 7.2(b) requires the methods for monitoring, measurement, analysis and evaluation to be determined so as to ensure valid results, which is a statement about method validity rather than about cadence or ownership. Point 7.2 also makes the risk assessment results and past significant incidents inputs to the policy.

Framework Mappings (18)

A&A-03Risk Based Planning Assessmentinformative
LOG-01Logging and Monitoring Policy and Proceduresinformative
A&A-03Risk Based Planning Assessmentinformative
LOG-01Logging and Monitoring Policy and Proceduresinformative
HIPAA-164.306.eMaintenancepartial
HIPAA-164.316.b.2.iiiUpdatesinformative
NIS2-Art.21.2.fAssessment of the Effectiveness of Risk-Management Measuresfull
NIS2-CIR-7Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk-Management Measurespartial
CA-7Continuous Monitoringfull
CA-7(4)Continuous Monitoring | Risk Monitoringpartial
PM-14Testing, Training, and Monitoringpartial
PM-31Continuous Monitoring Strategyfull
SI-6Security and Privacy Function Verificationpartial
MG-1.3-002High-Priority Risk Response Planning | MG-1.3-002full
MS-2.7-009AI System Security and Resilience Evaluation | MS-2.7-009informative
CC2.1COSO Principle 13: Uses Relevant Informationpartial
CC4.1COSO Principle 16: Conducts Ongoing or Separate Evaluationspartial
CC4.2COSO Principle 17: Evaluates and Communicates Deficienciespartial

Evidence (2)

policydocumentmanual

Continuous monitoring strategy document defining metrics, monitoring frequencies, tool coverage, and responsibilities.

Example: Continuous Monitoring Strategy (Confluence / ISMS document), listing: each monitored control domain, the metric or indicator used, the monitoring frequency, the tool or process performing the check, and the named role responsible for review.

Test: Request the continuous monitoring strategy document. Verify: (1) monitoring frequencies are defined per control domain or metric, (2) responsible roles are named, (3) the strategy has been approved by management and is dated within the last 12 months, (4) the strategy references how monitoring outputs feed into risk register updates.

reportdocumentmanual

Continuous monitoring output reports (dashboard, automated scan reports, or metric summaries) generated at the frequencies defined in the strategy.

Example: Security metrics dashboard export (Vanta / Drata / SIEM dashboard PDF) or weekly/monthly monitoring report, showing control health indicators and trend data, timestamped within the defined monitoring interval.

Test: Request monitoring output reports for the last two reporting cycles. Verify: (1) reports are timestamped within the defined frequency, (2) each metric or control indicator in the strategy has a corresponding data point, (3) anomalies or threshold breaches are flagged with a review or response record.

Questions (3)

boolean

Does your organisation have a documented continuous monitoring strategy?

The strategy should be documented, management-approved, and reference how monitoring outputs feed into risk register updates, not rely solely on annual audits.

multi

Which of the following continuous monitoring activities are currently operational in your organisation?

Automated vulnerability scanning on a defined scheduleSIEM or log aggregation with alert reviewCloud security posture management (CSPM) toolCompliance platform with automated control checks (e.g. Vanta, Drata)Scheduled manual control spot-checks between formal auditsNone of the above

Evidence should show monitoring outputs (dashboards, scan reports, alert logs) generated at the frequencies defined in the strategy.

multi

Which of the following does the continuous monitoring strategy record?

The metrics monitored for control effectivenessThe frequency of eachThe role accountable for reviewing eachWho a deviation is escalated toA link from each deviation to a risk register entry or a remediation recordNone of the above

Options run from the most commonly recorded to the least. Monitoring that produces output nobody is named to read is the common failure. A deviation with no link onward to a risk entry leaves the strategy reporting problems it never resolves.