Announcements
Voting is now open!
Members, make your selections in the annual (ISC)² Board of Directors election. Vote Now! Voting is open until Sept. 22.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
BIRISH
Viewer

Continuous Monitoring Plan (RMF)

I am looking for a good example of a Continuous Monitoring Policy/Plan/SOP (or all of the above) for use within the DoD RMF world.  Anyone?

3 Replies
tmekelburg1
Community Champion

Re: Continuous Monitoring Plan (RMF)

Here is one where they combine the policy and the NIST standards into one document. Personally, I'd make two separate documents but this is a start. Also, check out NIST SP 800-137 and 137A for more info on the subject. 

 

https://files.nc.gov/ncdit/documents/Statewide_Policies/SCIO_Security_Assessment_Authorization.pdf

AppDefects
Community Champion

Re: Continuous Monitoring Plan (RMF)

From a technical perspective I suggest thinking about the solution architecture and then adding the security monitoring components. I like storyboarding those kinds of solutions, they are more practical than paper policy.

RRoach
Newcomer III

Re: Continuous Monitoring Plan (RMF)

Each agency (there is roughly 100 command/service/agencies) has their own interpretation of continuous monitoring.  Start with looking at the specific agencies document structure (font/headings/etc.) to develop a template then tailor it. You also might be able to get some insight from DoD policies as well.