By Cyber Defense Technologies April 14, 2026 5 min read
The day a system receives its authorization to operate (ATO), its security posture begins to drift. Patches are released, configurations change, new users arrive, interconnections are added and adversaries find new techniques. An ATO based on an assessment months ago says little about the risk today.
Continuous monitoring, the final step of the Risk Management Framework (RMF), exists to close that gap. NIST SP 800-137 describes it as maintaining ongoing awareness of information security, vulnerabilities and threats to support risk management decisions.
Continuous monitoring in practice
-
1 Scan and collect
Vulnerability scans, configuration checks and log review on a set schedule.
-
2 Analyze
Correlate results with threats and prioritize by risk to the mission.
-
3 Respond
Remediate, mitigate or document risk acceptance, with POA&M updates.
-
4 Manage change
Assess security impact before changes reach production.
-
5 Report
Give the authorizing official current, honest risk status.
Then the cycle repeats.
What a monitoring strategy should define
A continuous monitoring strategy is documented as part of RMF and approved with the authorization. It should answer:
- What is monitored: controls, vulnerabilities, configurations, assets, accounts, logs and threats.
- How often: frequencies based on how quickly each item changes and how much risk it carries. Vulnerability scanning might be weekly; a policy review might be annual.
- How: automated tools where possible, manual reviews where necessary.
- Who: the roles responsible for performing, reviewing and acting on each activity.
- Reporting: what the authorizing official (AO) receives, how often, and what triggers an immediate report.
The core activities
Asset and configuration awareness
You cannot monitor what you do not know exists. Maintain accurate hardware and software inventories, and detect unauthorized devices and software. Compare actual configurations with approved baselines, such as STIG-hardened builds, and investigate drift.
Vulnerability management
Scan with credentials across the entire boundary on a set schedule, prioritize findings by exploitability and mission impact, and track remediation. Known exploited vulnerabilities, such as those in CISA's catalog, deserve urgency regardless of their base severity score.
Account and access review
Review privileged accounts, group memberships and access rights on a schedule. Confirm that departures and role changes were handled.
Log review and detection
Collect logs from security-relevant sources, correlate them, and alert on suspicious behavior. Evidence that someone reviews alerts and acts on them matters as much as the logs themselves.
Security impact analysis
Before a change reaches production, evaluate its effect on security: new ports, new software, new interconnections, changes to authentication. Some changes are significant enough to require reassessment or AO approval. This is the activity most often skipped, and the one that most often invalidates an authorization.
POA&M management
Monitoring findings feed the Plan of Action and Milestones. Items are added, updated and closed with evidence, and the POA&M is reviewed on a schedule with owners present.
Reporting that helps the AO
The AO's job is to decide whether risk remains acceptable. Reports should help with that decision:
- Trends, not only snapshots: Is the number of critical findings going up or down? Are POA&M dates holding?
- Exceptions highlighted: New high-risk findings, missed deadlines and significant changes.
- Plain language: What does a finding mean for the mission?
Toward ongoing authorization
When monitoring is mature, with frequent automated assessment, reliable reporting and disciplined change control, the AO can base authorization on current information rather than a periodic reassessment. NIST SP 800-37 calls this ongoing authorization. It replaces the cycle of a large reauthorization every few years with a steady, lower-effort process.
Common pitfalls
- Scanning without fixing. Findings accumulate in reports no one acts on.
- Partial coverage. Scans that skip segments, cloud workloads or network devices.
- Unauthenticated scans that miss most vulnerabilities.
- Changes without analysis. New features pushed without security review.
- Silent POA&Ms. Dates that pass without updates or explanation.
Setting monitoring frequencies
Not everything needs the same attention. A reasonable starting point, to be adjusted to the system's risk and the authorizing official's direction:
- Continuously or daily: security alerts and log review for high-risk events, endpoint protection status, and availability of security tools.
- Weekly: credentialed vulnerability scans, review of new critical and known exploited vulnerabilities, and review of unauthorized software or device alerts.
- Monthly: configuration compliance scans against baselines, POA&M review with owners, and patch compliance reporting.
- Quarterly: privileged account and access reviews, review of interconnections, and a sample of manual control checks.
- Annually: policy and procedure review, contingency plan testing, incident response exercises, and a broader reassessment of controls.
Frequencies should reflect how quickly a control can fail and how much damage a failure could cause. Controls that attackers target first, such as authentication, patching and privileged access, deserve the most frequent attention.
What an authorizing official wants to see each month
A one-page summary often works better than a large report:
- Counts of open critical and high findings, compared with last month
- Known exploited vulnerabilities outstanding, and their due dates
- POA&M items past due, with reasons and new dates
- Significant changes made, planned or pending security impact analysis
- Incidents and near misses, with lessons learned
- Any risk the team believes the AO should formally accept or reject
Consistent, honest reporting builds the trust that makes ongoing authorization possible.
How CDT can help
CDT designs and operates continuous monitoring programs, including scanning, configuration management, log review and reporting, through our RMF and ATO, DevSecOps and secure operations and managed security services.