Skip to main content
Category: Risk Management Framework

Monitor Step (RMF)

Also known as: RMF Monitor Step, Monitor Step, Step 7 (RMF)
Simply put

The Monitor Step is the phase of the Risk Management Framework where an organization keeps watch over its information systems after they are put into operation, checking that security and privacy protections continue to work as intended. Rather than being a one-time check, it is an ongoing activity that provides continuous awareness of a system's security posture and any changes in risk. This information supports decisions about whether a system should keep operating.

Formal definition

The Monitor Step is a step in the NIST Risk Management Framework whose stated purpose is to maintain ongoing situational awareness about the security and privacy posture of the system and organization to support risk management decisions. It generally encompasses continuous monitoring activities, including the ongoing assessment of the effectiveness of security and privacy controls, tracking changes to the system and its operating environment, and reassessing and reporting the current risk status throughout the system life cycle. As emphasized in the referenced guidance, it should be treated as an ongoing operational program rather than a scheduled annual assessment event; periodic reviews are one input to, not the entirety of, the continuous monitoring requirement. This entry describes the concept at a general level and does not detail specific control selections, monitoring frequencies, or agency-tailored implementation requirements, which practitioners should verify against the current authoritative NIST RMF publications and applicable organizational policy.

Why it matters

The Monitor Step is where the Risk Management Framework confronts a hard operational truth: an information system's security posture is not static. Controls that were effective at the moment of authorization can degrade as software is patched, personnel change, network boundaries shift, and adversary tactics evolve. Without ongoing monitoring, an organization is effectively relying on a point-in-time snapshot to justify continued operation of a system whose real risk may have moved substantially since that snapshot was taken. The purpose stated in NIST guidance, maintaining ongoing situational awareness about the security and privacy posture of the system and organization, exists precisely to close that gap and to keep risk decisions grounded in current conditions rather than historical ones.

A common and costly mistake is treating the Monitor Step as a scheduled annual assessment event rather than an ongoing operational program. As the referenced guidance emphasizes, periodic reviews such as annual assessments are one input to continuous monitoring, not the full requirement. Organizations that reduce monitoring to a once-a-year exercise create long windows in which control failures, configuration drift, and environmental changes go undetected. This also reinforces a related expert correction: an Authority to Operate is time-bound and conditioned on continuous monitoring, not a permanent grant. The information produced by the Monitor Step is what supports the risk management decisions, including whether a system should continue to operate, that keep an authorization meaningful over its life cycle.

It is also worth stressing that effective monitoring is not the same as compliance for its own sake. The value of the Monitor Step lies in generating actionable awareness of changes in risk, so that decision-makers can respond rather than simply attest that a checklist was completed. Practitioners should verify specific monitoring frequencies, control selections, and reporting expectations against the current authoritative NIST RMF publications and their own organizational policy, since these are tailored and can change across revisions.

Who it's relevant to

Information System Security Managers and Officers
Those responsible for a system's day-to-day security posture rely on the Monitor Step to identify when controls degrade, when the operating environment changes, and when risk status must be reassessed and reported. For them, the practical challenge is operating continuous monitoring as an ongoing program rather than defaulting to an annual review, since periodic assessments are only one input to the full requirement.
Authorizing Officials
Authorizing officials depend on the situational awareness produced during the Monitor Step to make informed risk management decisions, including whether a system should continue to operate. Because an Authority to Operate is time-bound and conditioned on continuous monitoring, the reporting generated in this step is central to keeping an authorization current rather than treating it as permanent.
Assessors and Auditors
Personnel who evaluate control effectiveness contribute to the ongoing assessment activities within the Monitor Step. They should distinguish assessment from authorization: an assessment provides evidence about control effectiveness and risk status, while the decision to continue operating a system rests with the authorizing official. Specific frequencies and scoping should be verified against current NIST RMF guidance and organizational policy.
Compliance Officers and Program Managers
Those managing compliance across a system's life cycle need to ensure that continuous monitoring is resourced and executed as an operational program. A recurring risk in this role is equating a completed annual review with satisfying the Monitor Step, when the standard calls for ongoing awareness of changes in risk throughout the life cycle.

Inside Monitor Step (RMF)

System and Environment Change Monitoring
Ongoing tracking of changes to the information system, its components, and its operational environment to determine whether such changes affect the security or privacy posture, generally as part of the Monitor step described in NIST SP 800-37 (verify against the applicable revision).
Ongoing Security and Privacy Control Assessments
Periodic or event-driven assessment of a subset of controls over time to confirm they remain implemented correctly, operating as intended, and producing the desired outcome, rather than relying solely on the point-in-time assessment performed before authorization.
Ongoing Risk Response and Remediation
Analysis of monitoring outputs to inform risk response decisions, including remediation actions, acceptance, or other treatment, feeding into plan of action and milestones tracking where applicable.
Authorization Maintenance
Review of the security and privacy posture on an ongoing basis so the authorizing official can determine whether the risk remains acceptable, supporting an ongoing authorization approach rather than treating the Authority to Operate as static.
Security and Privacy Reporting
Regular communication of security and privacy status to the authorizing official and other stakeholders so risk-based decisions can be made with current information.
System Disposal
Activities associated with implementing a system disposal strategy when a system is removed from operation, including handling of information, components, and residual risk in accordance with organizational policy.

Common questions

Answers to the questions practitioners most commonly ask about Monitor Step (RMF).

Does completing the Monitor Step mean my system's ATO stays valid indefinitely?
No. An Authority to Operate is time-bound and remains contingent on effective continuous monitoring. The Monitor Step is what sustains the authorization decision over time; it does not make an ATO permanent. If continuous monitoring reveals that risk has changed materially, the authorizing official may reassess, and the authorization can be revised or revoked. Many organizations move toward ongoing authorization models where the currency of the ATO depends directly on the quality of monitoring activities. Confirm your specific authorization terms and continuous monitoring requirements against your governing RMF documentation.
If I'm continuously monitoring controls, does that mean my system is secure and compliant?
Not necessarily. Monitoring demonstrates that you are tracking control effectiveness, security state, and changes to the system and its environment, but ongoing monitoring is a compliance and risk-management activity rather than a guarantee of security. A system can be fully within its monitoring cadence and still carry unremediated weaknesses tracked in a plan of action and milestones. Treat monitoring as evidence that risk is being observed and managed, not as proof that the system is free of vulnerabilities. Verify how your organization interprets acceptable residual risk against current authoritative guidance.
What activities generally fall within the Monitor Step?
In most RMF implementations, the Monitor Step includes tracking changes to the information system and its operating environment, conducting ongoing assessments of selected controls, performing ongoing risk assessments, maintaining current security documentation, reporting security status to the authorizing official and other stakeholders, and supporting decisions about ongoing authorization or system disposal. The specific set of activities and their frequency are typically defined in a continuous monitoring strategy. Confirm the precise activities and expectations against the applicable revision of your governing RMF publication and any agency tailoring.
How do I decide which controls to assess and how often during monitoring?
Assessment frequency is generally driven by a documented continuous monitoring strategy that prioritizes controls based on factors such as volatility, criticality to the security posture, and organizational risk tolerance. Controls that change frequently or are central to protecting the system are often assessed more often than stable controls. This prioritization is typically established at both the organization and system levels and coordinated with the authorizing official. Because cadences and prioritization criteria vary by agency and can change across revisions, confirm the current requirements and any agency-specific direction before setting your schedule.
What should I do when monitoring detects a change or a new weakness?
In general, changes to the system or environment should be evaluated for their security impact, and identified weaknesses should be documented and tracked, commonly through a plan of action and milestones. Significant changes may trigger reassessment of affected controls and reporting to the authorizing official, who evaluates whether the change alters the risk posture enough to affect the authorization. The exact thresholds for what constitutes a significant change and how it is escalated are typically defined in your monitoring strategy and agency procedures, which you should verify against current authoritative sources.
How does the Monitor Step relate to ongoing authorization and system disposal?
The information produced during the Monitor Step feeds authorization decisions over the system's life cycle. Where an ongoing authorization model is used, current monitoring data supports the authorizing official's continued acceptance of risk in near real time rather than relying solely on periodic reauthorization. The Monitor Step also supports secure system disposal by informing decisions about retiring components and handling information as the system approaches end of life. Because implementations of ongoing authorization and disposal procedures vary, confirm the specific processes your organization follows against its governing RMF guidance.

Common misconceptions

Once a system receives an Authority to Operate, the Monitor step is optional or the authorization is permanent.
An ATO is time-bound and conditioned on continuous monitoring. The Monitor step is intended to provide the ongoing visibility that keeps risk determinations current, and a deteriorating posture can lead the authorizing official to revisit or revoke authorization. Verify specific authorization terms against your organization's policy and current NIST guidance.
Continuous monitoring means every control is reassessed continuously or in real time.
In most implementations, ongoing assessment covers a defined subset of controls at frequencies determined by the organization's monitoring strategy, with emphasis on controls most volatile or most significant to risk. The cadence and scope are set by organizational tailoring rather than a universal real-time mandate.
The Monitor step is the same as the earlier Assess step, just repeated.
Assessment is one input to ongoing monitoring, but the Monitor step also encompasses change tracking, risk response, reporting to the authorizing official, and disposal. Assessment supports authorization decisions; it does not by itself constitute or replace the ongoing monitoring and authorization-maintenance activities of the Monitor step.

Best practices

Establish a documented continuous monitoring strategy that defines which controls are assessed, at what frequency, and by whom, and align that strategy with organizational and system-level risk tolerance.
Track changes to the system and its operating environment through a defined configuration and change management process, and evaluate each significant change for its effect on the security and privacy posture.
Feed monitoring results into an active plan of action and milestones process so that identified weaknesses are prioritized, remediated, or formally risk-accepted with authorizing official awareness.
Provide the authorizing official with regular, current security and privacy status reports so authorization decisions reflect the system's actual ongoing risk rather than a stale point-in-time snapshot.
Treat authorization as ongoing: use monitoring outputs to support reauthorization or ongoing authorization decisions and confirm that the ATO remains valid under current conditions.
Plan for system disposal in advance so that information handling, component sanitization, and residual risk are addressed in accordance with organizational policy when a system is retired, and verify the applicable requirements against current official sources.