Continuous Security Monitoring


Continuous security monitoring is maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions

  • NIST SP 800-137 provides a framework for continuous security monitoring

NIST SP 800-137 Framework

  • Continuous monitoring
    • Maps to risk tolerance
    • Adapts to ongoing needs
    • Actively involves management
  • Process
    1. Define
    2. Establish
    3. Implement
    4. Analyze/Report
    5. Respond
    6. Review/Update