Monitor Step (RMF)
The Monitor Step is the phase of the Risk Management Framework where an organization keeps watch over its information systems after they are put into operation, checking that security and privacy protections continue to work as intended. Rather than being a one-time check, it is an ongoing activity that provides continuous awareness of a system's security posture and any changes in risk. This information supports decisions about whether a system should keep operating.
The Monitor Step is a step in the NIST Risk Management Framework whose stated purpose is to maintain ongoing situational awareness about the security and privacy posture of the system and organization to support risk management decisions. It generally encompasses continuous monitoring activities, including the ongoing assessment of the effectiveness of security and privacy controls, tracking changes to the system and its operating environment, and reassessing and reporting the current risk status throughout the system life cycle. As emphasized in the referenced guidance, it should be treated as an ongoing operational program rather than a scheduled annual assessment event; periodic reviews are one input to, not the entirety of, the continuous monitoring requirement. This entry describes the concept at a general level and does not detail specific control selections, monitoring frequencies, or agency-tailored implementation requirements, which practitioners should verify against the current authoritative NIST RMF publications and applicable organizational policy.
Why it matters
The Monitor Step is where the Risk Management Framework confronts a hard operational truth: an information system's security posture is not static. Controls that were effective at the moment of authorization can degrade as software is patched, personnel change, network boundaries shift, and adversary tactics evolve. Without ongoing monitoring, an organization is effectively relying on a point-in-time snapshot to justify continued operation of a system whose real risk may have moved substantially since that snapshot was taken. The purpose stated in NIST guidance, maintaining ongoing situational awareness about the security and privacy posture of the system and organization, exists precisely to close that gap and to keep risk decisions grounded in current conditions rather than historical ones.
A common and costly mistake is treating the Monitor Step as a scheduled annual assessment event rather than an ongoing operational program. As the referenced guidance emphasizes, periodic reviews such as annual assessments are one input to continuous monitoring, not the full requirement. Organizations that reduce monitoring to a once-a-year exercise create long windows in which control failures, configuration drift, and environmental changes go undetected. This also reinforces a related expert correction: an Authority to Operate is time-bound and conditioned on continuous monitoring, not a permanent grant. The information produced by the Monitor Step is what supports the risk management decisions, including whether a system should continue to operate, that keep an authorization meaningful over its life cycle.
It is also worth stressing that effective monitoring is not the same as compliance for its own sake. The value of the Monitor Step lies in generating actionable awareness of changes in risk, so that decision-makers can respond rather than simply attest that a checklist was completed. Practitioners should verify specific monitoring frequencies, control selections, and reporting expectations against the current authoritative NIST RMF publications and their own organizational policy, since these are tailored and can change across revisions.
Who it's relevant to
Inside Monitor Step (RMF)
Common questions
Answers to the questions practitioners most commonly ask about Monitor Step (RMF).