Continuous Monitoring

February 12, 2018

How Can We Help?

You are here:
< Back

The process implemented to maintain a current security status for one or more information systems or for the entire suite of information systems on which the operational mission of the enterprise depends. The process includes: 1) The development of a strategy to regularly evaluate selected IA controls/metrics, 2) Recording and evaluating IA relevant events and the effectiveness of the enterprise in dealing with those events, 3) Recording changes to IA controls, or changes that affect IA risks, and 4) Publishing the current security status to enable information-sharing decisions involving the enterprise.
SOURCE: CNSSI-4009

Maintaining ongoing awareness to support organizational risk decisions.
SOURCE: SP 800-137