<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Continuous Monitoring Plan (RMF) in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43388#M309</link>
    <description>&lt;P&gt;Here is one where they combine the policy and the NIST standards into one document. Personally, I'd make two separate documents but this is a start. Also, check out NIST SP 800-137 and 137A for more info on the subject.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf" href="https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf" target="_blank" rel="noopener"&gt;https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 18:16:29 GMT</pubDate>
    <dc:creator>tmekelburg1</dc:creator>
    <dc:date>2021-02-17T18:16:29Z</dc:date>
    <item>
      <title>Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43385#M308</link>
      <description>&lt;P&gt;I am looking for a good example of a Continuous Monitoring Policy/Plan/SOP (or all of the above) for use within the DoD RMF world.&amp;nbsp; Anyone?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:48:13 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43385#M308</guid>
      <dc:creator>BIRISH</dc:creator>
      <dc:date>2023-10-09T09:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43388#M309</link>
      <description>&lt;P&gt;Here is one where they combine the policy and the NIST standards into one document. Personally, I'd make two separate documents but this is a start. Also, check out NIST SP 800-137 and 137A for more info on the subject.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf" href="https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf" target="_blank" rel="noopener"&gt;https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 18:16:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43388#M309</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-02-17T18:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43402#M314</link>
      <description>&lt;P&gt;From a technical perspective I suggest thinking about the solution architecture and then adding the security monitoring components. I like storyboarding those kinds of solutions, they are more practical than paper policy.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 02:44:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43402#M314</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2021-02-18T02:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43675#M336</link>
      <description>&lt;P&gt;Each agency (there is roughly 100 command/service/agencies) has their own interpretation of continuous monitoring.&amp;nbsp; Start with looking at the specific agencies document structure (font/headings/etc.) to develop a template then tailor it. You also might be able to get some insight from DoD policies as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 13:34:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/43675#M336</guid>
      <dc:creator>RRoach</dc:creator>
      <dc:date>2021-03-03T13:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/59292#M871</link>
      <description>&lt;P&gt;I am also looking for&amp;nbsp;&lt;SPAN&gt;Continuous Monitoring Strategy &amp;amp;&amp;nbsp;Continuous Monitoring Plan templates to satisfy the RMF controls. Anyone know where to find good templates please let us know. Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2023 22:38:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/59292#M871</guid>
      <dc:creator>JaceSin</dc:creator>
      <dc:date>2023-05-18T22:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/64176#M989</link>
      <description>&lt;P&gt;The team I'm on at HQDA G6 is working the ConMon strategy with other components. We will likely follow NIST SP 800-137 as a base but align with Sentinel's Army RMF 2.0 strategy and the Army Unified Network Plan. I will share any useful docs once we put them together and get the go ahead to distribute them. In the mean time I can recommend the FedRAMP continuous monitoring documents that also follow NIST 800-137.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 17:32:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/64176#M989</guid>
      <dc:creator>RMF_Expert</dc:creator>
      <dc:date>2023-11-03T17:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/78825#M1299</link>
      <description>do you happen to have any work breakdown structure for continuous monitoring?</description>
      <pubDate>Tue, 15 Apr 2025 11:06:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/78825#M1299</guid>
      <dc:creator>clane</dc:creator>
      <dc:date>2025-04-15T11:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Continuous Monitoring Plan (RMF)</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/78848#M1300</link>
      <description>&lt;P&gt;You can Start with templates aligned to NIST SP 800-137, 800-37,&amp;nbsp; and 800-53.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NIST SP 800-53 provides a comprehensive catalog of security and privacy controls&lt;BR /&gt;NIST SP 800-137 provide comprehensive guidance on establishing and assessing Information Security Continuous Monitoring (ISCM) programs.&lt;BR /&gt;NIST SP 800-37 outlines the RMF process, including the development and implementation of a continuous monitoring strategy at the organizational level. ​&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 21:51:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Continuous-Monitoring-Plan-RMF/m-p/78848#M1300</guid>
      <dc:creator>akkem</dc:creator>
      <dc:date>2025-04-15T21:51:08Z</dc:date>
    </item>
  </channel>
</rss>

