Skip to main content
Category: NIST Standards & Publications

NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

Also known as: ISCM, NIST SP 800-137, SP 800-137, Information Security Continuous Monitoring
Simply put

NIST SP 800-137 is a National Institute of Standards and Technology (NIST) publication that describes how organizations can keep ongoing awareness of their information security posture, vulnerabilities, and threats to support risk-based decisions. Rather than treating security as a one-time check, it promotes continuously watching systems so leaders can make informed decisions over time. A companion publication, NIST SP 800-137A, provides an approach for assessing how well an organization's continuous monitoring program is working.

Formal definition

NIST SP 800-137, titled 'Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations,' is a NIST Special Publication (final version authored by K. Dempsey, 2011) that establishes guidance for developing and implementing an ISCM strategy and program. It defines continuous monitoring as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. The publication is intended for federal information systems and organizations and supports risk management processes, and it is complemented by NIST SP 800-137A (2020), which provides an operational approach and evaluation criteria for assessing an organization's ISCM program. As NIST guidance, applicability to specific systems (for example, DoD RMF systems, national security systems, or non-federal environments) and any tailoring should be confirmed against the current authoritative text and the governing authorization requirements; readers should note that continuous monitoring under this framework supports, but does not by itself constitute, an ongoing authorization decision.

Why it matters

NIST SP 800-137 addresses a foundational problem in security compliance: a point-in-time assessment reflects a system's posture only on the day it was performed, while vulnerabilities, threats, and configurations change continuously afterward. By establishing guidance for an Information Security Continuous Monitoring (ISCM) program, the publication reframes security as an ongoing activity that maintains current awareness of an organization's information security posture, vulnerabilities, and threats so that leaders can make risk-based decisions over time rather than relying on stale snapshots.

This matters especially for compliance officers and authorizing officials because continuous monitoring supports risk management decisions but does not, by itself, constitute an ongoing authorization decision. An Authority to Operate remains a distinct, time-bound determination, and an effective ISCM program is one of the inputs that informs whether that authorization should continue, be reassessed, or be revoked. Treating an ATO as permanent, or assuming that a favorable initial assessment substitutes for sustained monitoring, is a common error that this framework is designed to counter.

The companion publication NIST SP 800-137A (2020) adds a further layer by providing an operational approach and evaluation criteria for assessing how well an organization's ISCM program is actually working. This distinction, between monitoring and assessing the monitoring program itself, reinforces that having a continuous monitoring capability on paper is not the same as demonstrating that it functions effectively. Readers should confirm applicability and any tailoring against the current authoritative NIST text and the governing authorization requirements for their specific environment.

Who it's relevant to

Authorizing Officials
Authorizing officials rely on continuous monitoring outputs to inform ongoing risk-based decisions about whether an authorization should continue. Because an ATO is time-bound and subject to continuous monitoring rather than permanent, the awareness maintained under an ISCM program is a key input to sustaining or reassessing that authorization. Officials should confirm how ISCM requirements are tailored under their governing authorization process.
Information System Security Managers and Program Staff
Those responsible for building and running a continuous monitoring capability can use NIST SP 800-137 as guidance for developing an ISCM strategy and program that maintains ongoing awareness of security posture, vulnerabilities, and threats. They can also use NIST SP 800-137A to evaluate whether the program they have implemented is actually working as intended.
Compliance Officers and Auditors
Compliance officers and auditors examining an organization's security program can reference these publications to distinguish between having a monitoring capability and demonstrating that it functions effectively. It is important to recognize that continuous monitoring supports risk management decisions but does not, by itself, constitute an authorization decision, and that compliance with monitoring guidance is not equivalent to security.
Federal Organizations and Practitioners in Non-Federal Environments
NIST SP 800-137 is intended for federal information systems and organizations. Practitioners in DoD RMF systems, national security systems, or non-federal environments should verify how, or whether, this guidance applies and what tailoring is required against the current authoritative NIST text and their governing authorization requirements, since applicability may differ across these contexts.

Inside ISCM

Information Security Continuous Monitoring (ISCM)
The core concept defined by NIST SP 800-137: maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. The publication frames ISCM as a continuous process rather than a point-in-time activity.
ISCM Strategy
The publication describes establishing an organization-wide strategy that generally aligns monitoring activities with risk tolerance and defines what is monitored, how frequently, and how results inform decisions. Specific frequencies and metrics are typically tailored by the organization.
Tiered Risk Management Alignment
SP 800-137 generally addresses continuous monitoring across organizational levels (such as organization, mission/business process, and information system tiers), consistent with the broader NIST risk management approach. Readers should verify the current tier structure against the applicable revision.
ISCM Process Steps
The guidance describes a process cycle that generally includes defining a strategy, establishing the program, implementing it, analyzing and reporting findings, responding to findings, and reviewing and updating the strategy. Exact step wording should be confirmed against the current authoritative text.
Relationship to the RMF
ISCM supports the ongoing authorization and monitoring activities within the NIST Risk Management Framework. It is guidance issued by NIST and is intended to inform, not replace, related publications such as SP 800-53 for control selection.

Common questions

Answers to the questions practitioners most commonly ask about ISCM.

Does implementing NIST SP 800-137 mean my system is continuously secure and no longer needs periodic reassessment?
No. NIST SP 800-137 defines a process for Information Security Continuous Monitoring (ISCM), but continuous monitoring is not a substitute for the broader authorization process or for periodic reassessment activities. Continuous monitoring generally supports ongoing awareness of security posture and informs risk-based decisions, but it does not by itself guarantee that a system remains secure. Compliance with the ISCM process should not be equated with security itself, and organizations should confirm how their monitoring strategy integrates with reassessment and reauthorization requirements under their applicable authority.
Does having an ISCM program under NIST SP 800-137 make an Authority to Operate (ATO) permanent?
No. An ATO remains time-bound and subject to continuous monitoring; establishing an ISCM program does not convert it into a permanent authorization. In many implementations, continuous monitoring supports an ongoing authorization model in which risk is assessed on an ongoing basis, but this still depends on the authorizing official's risk decisions and the organization's monitoring strategy. Readers should verify how their authorizing authority treats the relationship between continuous monitoring and authorization maintenance, as interpretations vary by agency and by applicable revision of governing guidance.
How does NIST SP 800-137 relate to the Risk Management Framework?
NIST SP 800-137 provides guidance for the continuous monitoring function that is generally associated with the ongoing steps of the RMF. In most implementations, the ISCM strategy and program described in SP 800-137 support the RMF's monitoring activities, including ongoing assessment of controls and reporting of security status. The precise integration depends on the applicable RMF guidance and any agency-specific tailoring, so organizations should confirm the current authoritative text and their own RMF processes rather than assuming a fixed mapping.
What should an ISCM strategy developed under NIST SP 800-137 generally address?
An ISCM strategy generally addresses what is monitored, how often monitoring occurs, how data is collected and analyzed, and how results inform risk-based decisions across organizational tiers. SP 800-137 describes continuous monitoring as spanning organization-wide, mission or business process, and information system levels. The specific metrics, frequencies, and thresholds are typically determined by the organization based on its risk tolerance and mission needs. Organizations should tailor these elements to their environment and verify expectations against current official guidance and any applicable agency direction.
How is monitoring frequency determined under NIST SP 800-137?
SP 800-137 generally frames monitoring frequency as a risk-based determination rather than a single fixed interval. In most implementations, the frequency for assessing a given control or metric is driven by factors such as the volatility of the control, its criticality to the security posture, and the organization's risk tolerance. Because this guidance is not prescriptive about exact intervals, organizations should document their rationale and confirm any specific frequency expectations imposed by their authorizing official or applicable agency requirements.
Does an ISCM program under NIST SP 800-137 need to feed information to authorizing officials?
Yes, in most implementations. A core purpose of continuous monitoring is to maintain ongoing awareness of security posture to support risk-based decision-making, which generally includes providing security status information to authorizing officials and other decision-makers. The specific reporting content, format, and cadence are typically defined in the organization's monitoring strategy. Organizations should confirm reporting expectations with their authorizing official and align them with any applicable agency reporting requirements.

Common misconceptions

Continuous monitoring under SP 800-137 means fully automated, real-time monitoring of every control.
The publication generally uses 'continuous' to mean ongoing awareness at organizationally defined frequencies, not necessarily real-time. Automation is encouraged where practical, but some monitoring activities remain manual or periodic, and frequencies are tailored to risk.
Implementing an ISCM program satisfies or replaces the need for an Authority to Operate (ATO).
ISCM supports ongoing authorization and continuous monitoring within the RMF, but monitoring is distinct from authorization. An ATO remains time-bound and subject to continuous monitoring; ISCM feeds authorization decisions rather than substituting for them.
SP 800-137 is a binding mandate that dictates specific metrics and monitoring frequencies.
SP 800-137 is NIST guidance describing a strategy and process; specific metrics, frequencies, and thresholds are generally defined by the organization based on risk tolerance. Binding requirements typically derive from other authorities, and applicability differs across civilian, defense, and national security systems.

Best practices

Define an organization-wide ISCM strategy that ties monitoring scope, frequencies, and metrics explicitly to documented risk tolerance rather than defaulting to generic or vendor-driven settings.
Align ISCM activities across organizational tiers so that system-level monitoring data rolls up to inform mission/business and organization-level risk decisions.
Integrate ISCM outputs into ongoing authorization and continuous monitoring processes so that findings drive timely response actions and support authorization decisions, not just reporting.
Treat monitoring frequencies as risk-based and revisit them regularly; verify chosen frequencies and metrics against the current applicable revision of the guidance and any overlaying agency requirements.
Automate collection and analysis where practical, while documenting which activities remain manual or periodic so gaps in awareness are understood and managed.
Periodically review and update the ISCM strategy and program to reflect changes in threats, systems, and organizational risk posture, and confirm details against current official NIST and agency sources.