background




Security Training & Awareness

RMF Continuous Monitoring





What Is RMF Continuous Monitoring?

Continuous Monitoring in a Risk Management Framework consists of continuous assessments, reporting, and authorization of information systems to monitor security risks.





Continuous Assessment

A system is continuously assessed according to the assessment frequency determined by its Risk Profile






Continuous Reporting

Regular risk reporting on assessment status allows for Continuous Monitoring of systems





Continuous Authorization

Once a Risk Profile SSP is assessed, the Authorizing Official (AO) determines whether the system can maintain its Authorization To Operate (ATO) and remain in Continuous Monitoring