NIST SP 800-37 Guidance for continuous monitoring ( Learn more in Building Cloud Products for Federal Agencies)

Elements essential to a successful organization-wide continuous monitoring program:

  • Configuration management and change control – develop processes for organizational information systems, throughout their SDLCs, and with consideration of their operating environments and their role(s) in supporting the organization’s missions and core business processes
  • Security impact analyses – develop security impact analysis and conduct analyses to monitor for changes to organizational information systems and their environments of operation for any adverse security impact to systems, mission/business and/or organizational functions which said systems support
  • (Ongoing) assessment of system security controls – assessment frequencies based on an organization-wide continuous monitoring strategy and individual system authorization strategies
  • Security status monitoring and reporting – communicate accurate and up-to-date security-related information to support ongoing management of information security risks and to enable data-driven risk mitigation decisions with minimal response times and acceptable data latencies; and
  • Active involvement of organizational officials.
  • Comprehensive ISCM strategy

A comprehensive ISCM strategy encompasses technology, processes, procedures, operating environments, and people.

This strategy includes:

  • Understanding of risk tolerance
  • Metrics that provide meaningful indications of security status at all organizational tiers
  • Continued effectiveness of all security controls
  • Verification of compliance with information security requirements
  • IT asset management
  • Knowledge and control of changes
  • Awareness of threats and vulnerabilities
  • An ISCM program is established to collect information in accordance with pre-established metrics, utilizing information readily available in part through implemented security controls.

FedRAMP Logo

Audit Velocity increases Maturity

  • Old approach: Find a flaw, fix a flaw
  • Better approach: Find flaws and keep a prioritized list
  • Best approach: Align vulnerability metrics into a continual service improvement model
  • CSP_Continuous_Monitoring_Strategy_Guide.pdf (fedramp.gov)
  • Information security continuous monitoring (ISCM) is defined as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions.
  • Please make room for protocol governance
Main Menu