Chapter 11

Strategies for Continuous Monitoring

Information in this chapter:

• Introduction to Continuous Monitoring

• The Continuous Monitoring Process

• Continuous Monitoring within FedRAMP

Introduction to Continuous Monitoring

Continuous1 monitoring (CM)2 is an organizational-wide activity that supports risk management by enabling an organization to understand and maintain its information security and risk posture through the collection, analysis, monitoring, and reporting of security-related information. To be effective, CM needs to be driven by the organization’s management to ensure it is managed as a part of the enterprise-wide risk management activity. This ensures monitoring is considered outside the context of a single information ...

Get Federal Cloud Computing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.