What Is RMF Continuous Monitoring?
Continuous Monitoring in a Risk Management Framework consists of continuous assessments, reporting, and authorization of information systems to monitor security risks.
Continuous Assessment
A system is continuously assessed according to the assessment frequency determined by its Risk Profile
Continuous Reporting
Regular risk reporting on assessment status allows for Continuous Monitoring of systems
Continuous Authorization
Once a Risk Profile SSP is assessed, the Authorizing Official (AO) determines whether the system can maintain its Authorization To Operate (ATO) and remain in Continuous Monitoring