Skip to main content
Category: Continuous Monitoring

Continuous Monitoring

Also known as: ConMon, Continuous Monitoring, Information Security Continuous Monitoring, ISCM
Simply put

Continuous Monitoring is the ongoing practice of regularly checking an information system's security controls, configuration, and risk posture rather than assessing it only once. It helps organizations detect new vulnerabilities, track changes, and maintain awareness of whether a system remains secure over time. In defense and federal compliance, it is a condition for keeping a system's authorization valid, because an authorization is time-bound and depends on demonstrating that security is being sustained.

Formal definition

Continuous Monitoring (ConMon), often expressed as Information Security Continuous Monitoring (ISCM), refers to the ongoing collection, analysis, and reporting of security-relevant information to maintain situational awareness of an information system's security state and to support risk-based decisions across its lifecycle. It generally encompasses activities such as ongoing control assessment, configuration and change management, vulnerability and threat monitoring, and periodic reporting to authorizing officials and other stakeholders. In the context of authorization, ConMon is a sustaining activity that supports an Authority to Operate (ATO), which is time-bound and subject to revocation if the monitored risk posture becomes unacceptable; it should not be treated as a one-time assessment, nor should the presence of a ConMon program be equated with a system being secure. Specific scope, frequency, metrics, and reporting obligations vary by framework, agency tailoring, impact level, and the applicable revision of governing guidance, and readers should verify requirements against current authoritative sources.

Why it matters

Continuous Monitoring matters because an authorization decision reflects a system's security and risk posture at a specific point in time, yet systems change constantly through patches, configuration drift, new vulnerabilities, evolving threats, and modifications to the operating environment. Without ongoing monitoring, an organization loses visibility into whether the conditions that justified an authorization still hold. In defense and federal compliance, an Authority to Operate (ATO) is time-bound and can be revoked if the monitored risk posture becomes unacceptable, so ConMon is generally treated as a condition for keeping an authorization valid rather than an optional enhancement.

A common and consequential mistake is treating authorization as a permanent state and viewing the initial assessment as the finish line. Under a risk management approach, authorization is a continuing obligation, and the presence of a ConMon program supports, but does not by itself guarantee, that a system remains secure. Equally important, having a monitoring program is not the same as being secure: monitoring generates the security-relevant information that supports risk-based decisions, but those decisions and any resulting remediation still have to be made and acted upon by responsible officials.

Because specific scope, frequency, metrics, and reporting obligations vary by framework, agency tailoring, impact level, and the applicable revision of governing guidance, organizations should confirm their exact ConMon requirements against current authoritative sources rather than assuming a single universal standard applies across civilian, defense, and other environments.

Who it's relevant to

Authorizing Officials (AOs)
Authorizing officials rely on Continuous Monitoring outputs to make ongoing, risk-based decisions about whether an authorization should remain in effect. Because an ATO is time-bound and subject to revocation, AOs use monitored risk information to determine whether the system's posture remains acceptable rather than treating the original authorization decision as permanent.
Information System Security Managers and Officers
These practitioners are typically responsible for operating the ConMon program day to day, including ongoing control assessment, configuration and change management, and vulnerability and threat monitoring. They translate monitoring activities into the periodic reporting that stakeholders and authorizing officials depend on.
Compliance Officers and Auditors
Compliance officers and auditors evaluate whether an organization sustains its authorized security posture over time, not just at initial assessment. They should distinguish assessment from authorization and confirm that a monitoring program is actually informing risk decisions, since the existence of ConMon activities alone does not establish that a system is secure.
Government Contractors
Contractors operating or supporting systems that must maintain authorization need to understand that ConMon obligations are ongoing conditions rather than one-time deliverables. Because scope, frequency, and reporting requirements vary by framework, agency tailoring, and impact level, contractors should verify the specific ConMon obligations that apply to their systems against the current authoritative guidance and any applicable contractual terms.

Inside ConMon

Ongoing Security Control Assessment
The periodic and event-driven reassessment of a subset of security controls to confirm they remain implemented correctly and effective over time, rather than being evaluated only once at initial authorization. The specific controls and frequencies are generally defined in a continuous monitoring strategy and may be tailored by the authorizing organization.
Ongoing Risk Determination and Acceptance
The recurring evaluation by the authorizing official (or delegate) of the system's current risk posture based on monitoring data, supporting decisions to maintain, adjust, or revoke authorization. This reflects that risk acceptance is not a one-time event but a continuing responsibility across the authorization period.
Security Status Reporting
The regular communication of system security state, vulnerabilities, and control effectiveness to relevant stakeholders, often through defined reporting cadences and dashboards. For FedRAMP-authorized systems, ConMon reporting to the FedRAMP PMO and authorizing agencies generally follows PMO-defined expectations, which differ from DoD RMF reporting practices.
Configuration and Change Management Monitoring
Tracking changes to the system, its components, and its boundary so that security-relevant modifications trigger appropriate reassessment. Significant changes may require additional assessment activity beyond routine monitoring, as determined by applicable policy and the ConMon strategy.
Vulnerability and Threat Monitoring
Ongoing scanning, analysis, and remediation tracking for known vulnerabilities and emerging threats affecting the system, typically documented through Plans of Action and Milestones (POA&Ms) where deficiencies are identified. Scan frequency and remediation timelines are generally set by the governing program or agency.

Common questions

Answers to the questions practitioners most commonly ask about ConMon.

Does receiving an Authority to Operate (ATO) mean my system is compliant and continuous monitoring is no longer needed?
No. An ATO is a time-bound authorization decision, not a permanent or one-time state, and it generally carries an ongoing obligation to maintain the system's security posture through continuous monitoring. In most implementations, the authorizing official's decision is premised on the expectation that the organization will keep assessing controls, tracking changes, and reporting security-relevant information over the life of the authorization. ConMon is what sustains the basis for the ATO between formal reauthorization events; it is not a phase that ends once authorization is granted. Readers should confirm the specific monitoring frequency and reporting expectations tied to their authorization against the applicable governing guidance and any conditions set by their authorizing official.
If my continuous monitoring program shows I am meeting all my controls, does that mean my system is secure?
Not necessarily. Demonstrating that assessed controls remain in place addresses compliance with a defined baseline, but compliance and security are distinct concepts. Continuous monitoring is designed to give decision-makers ongoing awareness of the security state and risk of a system, yet a monitored control set reflects the assumptions, tailoring, and threat picture in effect at the time it was defined. Emerging threats, misconfigurations outside the monitored scope, or gaps between what is assessed and what is operationally exploitable can leave residual risk even when monitoring results appear favorable. ConMon supports risk-informed decisions; it does not by itself guarantee that a system is secure against all relevant threats.
How do we determine how often continuous monitoring activities should occur?
Monitoring frequency is generally risk-based and varies by the criticality and volatility of the control, the system's impact level, and any conditions imposed by the authorizing official. In most implementations, more dynamic or higher-risk elements are assessed more frequently than stable controls, and organizations document these frequencies in a monitoring strategy. Specific cadence expectations can differ across federal civilian systems under FISMA, DoD systems under the RMF, and cloud services under FedRAMP, so the applicable frequencies should be confirmed against the current governing guidance and program-specific requirements rather than assumed to be uniform.
What types of activities are typically included in a continuous monitoring program?
Continuous monitoring commonly encompasses ongoing assessment of a subset of controls, configuration and change management, vulnerability and status information collection, and security-relevant reporting to support risk decisions. In many programs this includes maintaining an accurate inventory, tracking deviations, and updating documentation such as the system security plan and plan of action and milestones as conditions change. The precise composition of activities depends on the governing framework and organizational tailoring, and this entry does not address specific tooling, automation, or contractual implementation details, which readers should verify against current authoritative sources.
How does continuous monitoring relate to reauthorization and the ongoing role of the authorizing official?
Continuous monitoring generally provides the authorizing official with the ongoing information needed to make risk decisions between and leading up to formal reauthorization actions. In many implementations, the outputs of the monitoring program inform whether the existing authorization remains acceptable, whether additional actions are needed, or whether a reauthorization is warranted. This supports the concept of ongoing authorization in some environments. The specific triggers, thresholds, and decision procedures are set by the applicable governing guidance and the authorizing official, and readers should confirm these against their program's current requirements.
How should we handle new vulnerabilities or findings identified through continuous monitoring?
Findings surfaced through monitoring are generally documented, assessed for risk, and tracked to remediation, often through a plan of action and milestones or equivalent mechanism, with reporting to the appropriate stakeholders. In most implementations the response is prioritized based on risk and any timelines established by the governing framework or the authorizing official. This entry does not specify remediation deadlines, severity scoring methods, or agency-specific reporting workflows, which can differ across FISMA, RMF, and FedRAMP contexts and should be verified against current official sources and applicable contractual terms.

Common misconceptions

An Authority to Operate (ATO) is granted once and remains valid indefinitely, so continuous monitoring is optional maintenance.
An ATO is time-bound and conditioned on ongoing risk acceptance. Continuous monitoring is a core element of maintaining an authorization; degraded security posture or failure to meet monitoring obligations can lead an authorizing official to reassess or revoke the authorization.
Passing continuous monitoring checks means the system is secure.
Continuous monitoring measures whether selected controls remain compliant and effective against defined criteria; it is not equivalent to demonstrating comprehensive security. Compliance and security are related but distinct, and monitoring covers a defined scope that may not address every threat or residual risk.
FedRAMP continuous monitoring reporting automatically satisfies DoD continuous monitoring requirements.
FedRAMP authorization and its ConMon practices are maintained under the FedRAMP PMO for federal cloud services, while DoD systems operate under the RMF with DoD-specific expectations. A FedRAMP authorization does not automatically meet DoD requirements, and readers should verify obligations against the applicable current authoritative guidance.

Best practices

Establish a documented continuous monitoring strategy that specifies which controls are monitored, at what frequency, and by whom, and align it with the applicable governing framework (for example RMF or FedRAMP PMO expectations) rather than assuming a single universal cadence.
Treat the ATO as time-bound and maintain the monitoring evidence and reporting needed to support the authorizing official's ongoing risk acceptance throughout the authorization period.
Integrate configuration and change management so that security-relevant changes trigger reassessment, and evaluate whether a change is significant enough to require assessment beyond routine monitoring.
Maintain and actively manage POA&Ms for identified deficiencies, tracking remediation against timelines defined by the governing program or agency.
Provide security status reporting to stakeholders on the required cadence, and confirm reporting formats and recipients against the current authoritative expectations for your system's framework.
Verify continuous monitoring obligations against current official sources, since control baselines, frequencies, and reporting requirements can change across revisions and be tailored by the authorizing organization.