NIH | National Cancer Institute | NCI Wiki  

Error rendering macro 'rw-search'

null

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

Systems enter the Continuous Monitoring Phase, Step 6 of the NIST Risk Management Framework (RMF), after achieving authorization to operate (ATO).  The purpose of this phase is to provide oversight and monitoring of the security controls in the information system on an ongoing basis and to inform the Authorizing Official (AO) when changes occur that may impact the security of the system.  CM  consists of three tasks:

  1.  Configuration management and control;
  2.  Security control monitoring; and
  3.  Status reporting and documentation, which are performed continuously throughout the life cycle of an information system.
  • No labels