Continuous Monitoring
Continuous Monitoring is the ongoing practice of regularly checking an information system's security controls, configuration, and risk posture rather than assessing it only once. It helps organizations detect new vulnerabilities, track changes, and maintain awareness of whether a system remains secure over time. In defense and federal compliance, it is a condition for keeping a system's authorization valid, because an authorization is time-bound and depends on demonstrating that security is being sustained.
Continuous Monitoring (ConMon), often expressed as Information Security Continuous Monitoring (ISCM), refers to the ongoing collection, analysis, and reporting of security-relevant information to maintain situational awareness of an information system's security state and to support risk-based decisions across its lifecycle. It generally encompasses activities such as ongoing control assessment, configuration and change management, vulnerability and threat monitoring, and periodic reporting to authorizing officials and other stakeholders. In the context of authorization, ConMon is a sustaining activity that supports an Authority to Operate (ATO), which is time-bound and subject to revocation if the monitored risk posture becomes unacceptable; it should not be treated as a one-time assessment, nor should the presence of a ConMon program be equated with a system being secure. Specific scope, frequency, metrics, and reporting obligations vary by framework, agency tailoring, impact level, and the applicable revision of governing guidance, and readers should verify requirements against current authoritative sources.
Why it matters
Continuous Monitoring matters because an authorization decision reflects a system's security and risk posture at a specific point in time, yet systems change constantly through patches, configuration drift, new vulnerabilities, evolving threats, and modifications to the operating environment. Without ongoing monitoring, an organization loses visibility into whether the conditions that justified an authorization still hold. In defense and federal compliance, an Authority to Operate (ATO) is time-bound and can be revoked if the monitored risk posture becomes unacceptable, so ConMon is generally treated as a condition for keeping an authorization valid rather than an optional enhancement.
A common and consequential mistake is treating authorization as a permanent state and viewing the initial assessment as the finish line. Under a risk management approach, authorization is a continuing obligation, and the presence of a ConMon program supports, but does not by itself guarantee, that a system remains secure. Equally important, having a monitoring program is not the same as being secure: monitoring generates the security-relevant information that supports risk-based decisions, but those decisions and any resulting remediation still have to be made and acted upon by responsible officials.
Because specific scope, frequency, metrics, and reporting obligations vary by framework, agency tailoring, impact level, and the applicable revision of governing guidance, organizations should confirm their exact ConMon requirements against current authoritative sources rather than assuming a single universal standard applies across civilian, defense, and other environments.
Who it's relevant to
Inside ConMon
Common questions
Answers to the questions practitioners most commonly ask about ConMon.