NIST SP 800-37 Guidance for continuous monitoring ( Learn more in Building Cloud Products for Federal Agencies)
Elements essential to a successful organization-wide continuous monitoring program:
- Configuration management and change control – develop processes for organizational information systems, throughout their SDLCs, and with consideration of their operating environments and their role(s) in supporting the organization’s missions and core business processes
- Security impact analyses – develop security impact analysis and conduct analyses to monitor for changes to organizational information systems and their environments of operation for any adverse security impact to systems, mission/business and/or organizational functions which said systems support
- (Ongoing) assessment of system security controls – assessment frequencies based on an organization-wide continuous monitoring strategy and individual system authorization strategies
- Security status monitoring and reporting – communicate accurate and up-to-date security-related information to support ongoing management of information security risks and to enable data-driven risk mitigation decisions with minimal response times and acceptable data latencies; and
- Active involvement of organizational officials.
- Comprehensive ISCM strategy
A comprehensive ISCM strategy encompasses technology, processes, procedures, operating environments, and people.
This strategy includes:
- Understanding of risk tolerance
- Metrics that provide meaningful indications of security status at all organizational tiers
- Continued effectiveness of all security controls
- Verification of compliance with information security requirements
- IT asset management
- Knowledge and control of changes
- Awareness of threats and vulnerabilities
- An ISCM program is established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls.

Audit Velocity increases Maturity
- Old approach: Find a flaw, fix a flaw
- Better approach: Find flaws and keep a prioritized list
- Best approach: Align vulnerability metrics into a continual service improvement model
- CSP_Continuous_Monitoring_Strategy_Guide.pdf (fedramp.gov)
- Information security continuous monitoring (ISCM) is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions.
- Please make room for protocol governance

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics