3.6 Continuous Monitoring Strategy & Control Selection Approval

Key Takeaways

  • RMF Step 2 concludes with the development of the System-Level Continuous Monitoring (ISCM) Strategy aligned with NIST SP 800-137 enterprise governance.
  • Assessment frequencies within the monitoring strategy are determined by control volatility, system criticality, threat dynamics, and environmental changes.
  • The Security Control Assessor (SCA) conducts early reviews of planned controls and compensating justifications to verify testability and prevent downstream compliance failures.
  • Formal approval and sign-off on the System Security Plan (SSP) and ISCM Strategy by the Authorizing Official (AO) represents the mandatory milestone gate to enter Step 3 (Implement).
  • Executing control implementation prior to formal AO baseline approval creates severe project risk, architectural rework, and audit non-compliance.
Last updated: August 2026

3.6 Continuous Monitoring Strategy & Control Selection Approval

Core Blueprint Focus: Selecting controls is not merely an academic exercise—it culminates in two binding governance milestones: establishing the System Continuous Monitoring (ISCM) Strategy (Task S-5) and securing formal Authorizing Official (AO) Approval of the Security Plan (Task S-6). RMF Step 2 establishes the baseline against which all subsequent engineering, assessment, and authorization activities are judged.

Once the security and privacy controls have been selected, tailored, and allocated, the organization must establish how those controls will be monitored over time and obtain formal executive authorization from the Authorizing Official (AO) before committing engineering capital to implementation.


RMF Step 2: Task-by-Task Execution Breakdown

According to NIST SP 800-37 Rev. 2, Step 2 (Select) comprises six sequential tasks that transform risk categorization into an approved, assessor-ready control implementation blueprint:

┌─────────────────────────────────────────────────────────────────────────────┐
│                     RMF STEP 2 (SELECT) TASK SEQUENCE                       │
│                                                                             │
│  Task S-1: CONTROL SELECTION                                                │
│  • Select initial control baseline (NIST SP 800-53B Low/Mod/High + Privacy) │
│                                                                             │
│  Task S-2: CONTROL TAILORING                                                │
│  • Apply scoping guidance, parameterize ODPs, select compensating controls  │
│                                                                             │
│  Task S-3: CONTROL ALLOCATION                                               │
│  • Designate controls as Common, Inherited, Hybrid, or System-Specific      │
│                                                                             │
│  Task S-4: DOCUMENTATION OF PLANNED CONTROL IMPLEMENTATIONS                 │
│  • Draft Control Implementation Statements in the System Security Plan (SSP)│
│                                                                             │
│  Task S-5: CONTINUOUS MONITORING STRATEGY - SYSTEM                          │
│  • Define metrics, assessment frequencies, and ongoing monitoring mechanisms│
│                                                                             │
│  Task S-6: PLAN REVIEW AND APPROVAL                                         │
│  • Formal AO sign-off on SSP and Continuous Monitoring Strategy (Gate)      │
└─────────────────────────────────────────────────────────────────────────────┘

Developing the System Continuous Monitoring (ISCM) Strategy (NIST SP 800-137)

An effective Information Security Continuous Monitoring (ISCM) program, governed by NIST SP 800-137, ensures that security controls maintain their operational efficacy throughout the system life cycle. While Tier 1 and Tier 2 establish enterprise monitoring policies, Task S-5 requires the Information System Owner (ISO) and ISSO to author a system-level continuous monitoring strategy tailored to the system's operational environment.

┌─────────────────────────────────────────────────────────────────────────────┐
│               CORE PILLARS OF A SYSTEM-LEVEL ISCM STRATEGY                  │
│                                                                             │
│  1. METRICS & KEY RISK INDICATORS (KRIs)                                    │
│     • Quantifiable security metrics (e.g., patch latency, failed logins).  │
│                                                                             │
│  2. ASSESSMENT FREQUENCIES (VOLATILITY-BASED)                               │
│     • Real-Time/Continuous: Configuration baselines, automated CVE scans.   │
│     • Monthly/Quarterly: Audit log reviews, vulnerability assessments.      │
│     • Annual: Contingency plan exercises, physical security reviews.        │
│                                                                             │
│  3. MONITORING MECHANISMS & AUTOMATION                                      │
│     • SCAP-compliant scanners, SIEM/SOAR pipelines, automated CSPM tools.   │
│                                                                             │
│  4. POSTURE REPORTING & ESCALATION PATHWAYS                                 │
│     • Scheduled dashboards to AO; immediate alerts on critical zero-days.   │
└─────────────────────────────────────────────────────────────────────────────┘

Determining Assessment Frequencies: The Control Volatility Principle

Not all controls require the same monitoring interval. Assessment frequencies in the ISCM strategy are determined by Control Volatility—the likelihood that a control's operational configuration or effectiveness will degrade over time:

Volatility LevelControl CharacteristicsExample ControlsTarget Assessment Frequency
High VolatilityTechnical controls directly exposed to rapid operational drift, software updates, and immediate network threats.CM-6 (Configuration Settings)<br>SI-2 (Flaw Remediation / Patching)<br>SI-4 (Malicious Code / EDR)<br>AC-2 (Account Audits)Continuous / Daily / Weekly (Automated scanning via SIEM, EDR, SCAP tools)
Moderate VolatilityOperational and procedural controls that undergo periodic administrative adjustment or review cycles.AU-6 (Audit Review & Analysis)<br>CA-7 (Continuous Monitoring)<br>RA-5 (Vulnerability Scanning)<br>SA-9 (External Provider Reviews)Monthly / Quarterly (Automated reports + manual assessor reviews)
Low VolatilityFoundational management, environmental, and governance policies that remain stable over long periods.PE-3 (Physical Badge Access)<br>PL-2 (System Security Plan Updates)<br>PS-3 (Personnel Screening)<br>CP-4 (Contingency Plan Testing)Annually / Multi-Year (Formal tabletop tests, physical inspections, policy audits)

Stakeholder Review & Collaborative Governance Roles

Before the tailored control baseline is submitted to the Authorizing Official for formal approval, a multi-disciplinary review must occur to ensure technical accuracy, legal compliance, and testability:

┌─────────────────────────────────────────────────────────────────────────────┐
│                     STEP 2 STAKEHOLDER REVIEW WORKFLOW                      │
│                                                                             │
│   ┌──────────────────────────┐             ┌──────────────────────────┐     │
│   │  ISO / ISSO / Engineers  │ ──────────► │ Security Control Assessor│     │
│   │  Drafts SSP & CIS        │             │ Early Testability Review │     │
│   └──────────────────────────┘             └────────────┬─────────────┘     │
│                                                         │                   │
│                                                         ▼                   │
│   ┌──────────────────────────┐             ┌──────────────────────────┐     │
│   │  SAOP / Privacy Officer  │ ──────────► │ Authorizing Official (AO)│     │
│   │  Validates Privacy Base  │             │ Formal Approval & Signoff│     │
│   └──────────────────────────┘             └──────────────────────────┘     │
└─────────────────────────────────────────────────────────────────────────────┘

Core Stakeholder Responsibilities in Step 2:

  1. Information System Owner (ISO) & Information System Security Officer (ISSO): Author the System Security Plan (SSP), draft Control Implementation Statements (CIS), formulate the continuous monitoring strategy, and coordinate engineering feasibility.
  2. Security Control Assessor (SCA): Conducts an early testability review of the planned controls. The SCA evaluates whether planned implementation statements are clear, measurable, and verifiable, and reviews proposed compensating controls and scoping exclusions. Engaging the SCA during Step 2 prevents catastrophic surprises during RMF Step 4 (Assess).
  3. Senior Agency Official for Privacy (SAOP) / Chief Privacy Officer (CPO): Reviews all privacy baseline allocations, verifies Authority to Process PII (PT-1), approves privacy notices (PT-2), and ensures compliance with the Privacy Act and E-Government Act.
  4. Authorizing Official Designated Representative (AODR): Assists the AO by managing administrative reviews, liaising with program managers, and verifying that the risk posture aligns with enterprise risk tolerance.
  5. Authorizing Official (AO) / Delegated Authorizing Official (DAO): The senior executive who holds formal statutory and budgetary authority. The AO reviews the tailored baseline, evaluates residual risk and compensating controls, and officially signs the Security Plan.

Resolving Tailoring Disagreements & Compensating Control Approvals

During the Step 2 review, friction frequently arises between system developers seeking flexible operational baselines and security assessors demanding strict compliance:

  • Challenging Inapplicable Scoping Exclusions: If an ISO attempts to scope out a control without sufficient technical justification (e.g., scoping out SI-4 intrusion detection due to budget limits), the SCA and AODR will flag the exclusion as non-compliant, forcing the ISO to restore the control or engineer a valid compensating safeguard.
  • Compensating Control Validation: The AO and SCA rigorously examine compensating control proposals. If a compensating control does not offer equivalent risk mitigation, the AO will reject the proposal, requiring architectural redesign before approving the Security Plan.
  • Risk Escalation to the Risk Executive (Function): If a tailoring decision introduces systemic enterprise risk that exceeds the AO's individual risk threshold, the decision is escalated to the Tier 1 Risk Executive (Function) for enterprise-wide risk adjudication.

Formal Milestone Sign-Off: The Gate to Step 3 (Implement)

[!IMPORTANT] The RMF Milestone Gate: The formal approval of the System Security and Privacy Plan (SSP/SSPP) and the Continuous Monitoring Strategy by the Authorizing Official (Task S-6) constitutes the official governance gate allowing the project to proceed to RMF Step 3 (Implement).

+-----------------------------------------------------------------------------+
|                   RMF STEP 2 TO STEP 3 MILESTONE TRANSITION                 |
|                                                                             |
|   RMF STEP 2 (SELECT)                    RMF STEP 3 (IMPLEMENT)             |
|   [Task S-1: Control Selection   ]                                          |
|   [Task S-2: Control Tailoring   ]                                          |
|   [Task S-3: Control Allocation  ]                                          |
|   [Task S-4: SSP Documentation   ]                                          |
|   [Task S-5: Monitoring Strategy ]                                          |
|   [Task S-6: AO Plan Approval    ] ===(GATE)===> [Task I-1: Control Impl.  ] |
|                                                  [Task I-2: SSP Update     ] |
+-----------------------------------------------------------------------------+

Why Pre-Approval Implementation is a Critical Risk:

Initiating system coding, cloud provisioning, or hardware acquisition without formal AO baseline approval creates severe programmatic and compliance risks:

  • Architectural Rework: Engineering teams may implement configurations that the AO or SCA subsequently rejects, resulting in expensive refactoring.
  • Unapproved Risk Exposure: The system may operate with unacknowledged vulnerabilities outside organizational risk tolerance.
  • Audit Non-Compliance: Federal and commercial audit frameworks (e.g., FISMA, FedRAMP, SOC 2) treat undocumented or unapproved baseline modifications as formal material weaknesses.

RMF Step 2 Tasks, Responsible Roles & Deliverables

Task IDTask NamePrimary Responsible RoleKey Input ArtifactsOutput Deliverable Artifact
S-1Control SelectionISO, ISSO, SAOPFIPS 199 Categorization Report, NIST SP 800-53BInitial Security & Privacy Control Baseline
S-2Control TailoringISO, ISSO, Security EngineersThreat Intelligence, System Architecture, OverlaysTailored Control Set with Parameterized ODPs
S-3Control AllocationISO, CCP, Enterprise ArchitectCommon Control Catalog, Cloud CRM / CISControl Allocation Matrix (Common, Hybrid, Specific)
S-4Documentation of ControlsISO, ISSOSystem Architecture, Data Flow DiagramsDraft System Security and Privacy Plan (SSP/SSPP)
S-5Continuous Monitoring StrategyISO, ISSO, Enterprise CISONIST SP 800-137, Enterprise ISCM PolicySystem Information Security Continuous Monitoring Plan
S-6Plan Review and ApprovalAuthorizing Official (AO) / SAOPComplete SSP, ISCM Plan, Risk Assessment ReportFormally Approved & Signed System Security Plan

Real-World RMF Scenario: Securing AO Approval for a High-Risk Cloud Migration

Scenario: A federal agency is migrating a national defense logistics database to a commercial cloud environment. The ISO submits an SSP containing three critical compensating controls for legacy database replication protocols that lack native TLS 1.3 encryption. The Security Control Assessor (SCA) reviews the draft plan and notes that while the compensating IPsec tunnels provide strong data-in-transit encryption, the monitoring strategy lacks automated alerting for tunnel degradation.

GRC Action: During the Task S-5 review, the ISSO updates the Continuous Monitoring Strategy to include real-time SNMP/Syslog heartbeat alerts integrated into the enterprise SIEM. The SCA validates that the compensating control is now fully verifiable and monitored. The Authorizing Official (AO) conducts the Task S-6 review, confirms that the residual risk aligns with organizational risk tolerance, and formally signs the System Security Plan, officially authorizing the project to begin Step 3 (Implement).

Loading diagram...
RMF Step 2 (Select) Milestone Review & AO Approval Gate Workflow
Test Your Knowledge

According to NIST SP 800-137 and RMF continuous monitoring principles, how should an Information System Security Officer (ISSO) determine the assessment frequency for specific security controls in the System Continuous Monitoring Strategy?

A
B
C
D
Test Your Knowledge

Why is the Security Control Assessor (SCA) encouraged to participate in the review of the System Security Plan and tailored control baseline during RMF Step 2 (Select), well before formal testing begins in Step 4 (Assess)?

A
B
C
D
Test Your Knowledge

What is the mandatory governance outcome of RMF Step 2 Task S-6 (Plan Review and Approval) that officially authorizes an engineering project to proceed to Step 3 (Implement)?

A
B
C
D