NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
NIST SP 800-137 is a National Institute of Standards and Technology (NIST) publication that describes how organizations can keep ongoing awareness of their information security posture, vulnerabilities, and threats to support risk-based decisions. Rather than treating security as a one-time check, it promotes continuously watching systems so leaders can make informed decisions over time. A companion publication, NIST SP 800-137A, provides an approach for assessing how well an organization's continuous monitoring program is working.
NIST SP 800-137, titled 'Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations,' is a NIST Special Publication (final version authored by K. Dempsey, 2011) that establishes guidance for developing and implementing an ISCM strategy and program. It defines continuous monitoring as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. The publication is intended for federal information systems and organizations and supports risk management processes, and it is complemented by NIST SP 800-137A (2020), which provides an operational approach and evaluation criteria for assessing an organization's ISCM program. As NIST guidance, applicability to specific systems (for example, DoD RMF systems, national security systems, or non-federal environments) and any tailoring should be confirmed against the current authoritative text and the governing authorization requirements; readers should note that continuous monitoring under this framework supports, but does not by itself constitute, an ongoing authorization decision.
Why it matters
NIST SP 800-137 addresses a foundational problem in security compliance: a point-in-time assessment reflects a system's posture only on the day it was performed, while vulnerabilities, threats, and configurations change continuously afterward. By establishing guidance for an Information Security Continuous Monitoring (ISCM) program, the publication reframes security as an ongoing activity that maintains current awareness of an organization's information security posture, vulnerabilities, and threats so that leaders can make risk-based decisions over time rather than relying on stale snapshots.
This matters especially for compliance officers and authorizing officials because continuous monitoring supports risk management decisions but does not, by itself, constitute an ongoing authorization decision. An Authority to Operate remains a distinct, time-bound determination, and an effective ISCM program is one of the inputs that informs whether that authorization should continue, be reassessed, or be revoked. Treating an ATO as permanent, or assuming that a favorable initial assessment substitutes for sustained monitoring, is a common error that this framework is designed to counter.
The companion publication NIST SP 800-137A (2020) adds a further layer by providing an operational approach and evaluation criteria for assessing how well an organization's ISCM program is actually working. This distinction, between monitoring and assessing the monitoring program itself, reinforces that having a continuous monitoring capability on paper is not the same as demonstrating that it functions effectively. Readers should confirm applicability and any tailoring against the current authoritative NIST text and the governing authorization requirements for their specific environment.
Who it's relevant to
Inside ISCM
Common questions
Answers to the questions practitioners most commonly ask about ISCM.