✳ US · NIST SP 800-137

SP 800-137: Information Security Continuous Monitoring (not Authorize forever, not a SIEM)

An educational overview of NIST SP 800-137 (Date Published September 2011, Final 2011-09-30) as guidance for an Information Security Continuous Monitoring (ISCM) strategy and program for federal information systems and organizations. It names SP 800-137A only. Not the seven RMF steps finished, not a FedRAMP package, not a SIEM, not an SP 800-30 assessment, and not an Atlas Authorization to Operate.

US · NIST SP 800-137Publication explainerLast reviewed

What category of publication this is

NIST Special Publication 800-137 is Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. The CSRC abstract says its purpose is to help organizations develop a continuous monitoring strategy and implement a continuous monitoring program. That program is meant to provide visibility into organizational assets, awareness of threats and vulnerabilities, and visibility into the effectiveness of deployed security controls. It supports ongoing assurance that planned and implemented controls stay aligned with organizational risk tolerance, and it supplies information needed to respond when observations suggest the controls are inadequate.

Who it commonly frames: readers leaving the Risk Management Framework page and the SP 800-30 assessment page who still treat a monitoring dashboard as Authorization, and public sector or GRC readers who meet continuous monitoring as a slogan. It is a publication. It is not a statute, and it is not a scoring product.

What security people most often confuse: they fold continuous monitoring, the seven RMF steps, a FedRAMP package, a SIEM purchase, and an SP 800-30 assessment into one homework pile. This page keeps those objects apart.

Edition pin

SP 800-137, Date Published September 2011. Document history on the CSRC page stamps Final on 2011-09-30 (shown there as 09/30/11). DOI 10.6028/NIST.SP.800-137. The PDF is nistspecialpublication800-137 on nvlpubs. The NIST publications page lists the same publication date, September 30, 2011.

Document history on that CSRC page has one Final stamp, 2011-09-30. SP 800-137 is the current Final there as of this review (2026-09-26). If a newer Final appears, update this pin and treat the older claim as UNKNOWN.

One definition, and what continuous means

The executive summary and Chapter 1 define information security continuous monitoring (ISCM) as maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions.

A footnote in Chapter 1 says the words continuous and ongoing, in this context, mean that security controls and organizational risks are assessed and analyzed at a frequency sufficient to support risk-based security decisions. Data collection, no matter how frequent, is performed at discrete intervals. This page does not invent collection intervals, metrics, or service levels.

Where this publication sits

SP 800-137 (2011) describes ISCM as part of the Risk Management Framework and says information collected through the program supports ongoing authorization decisions. The seven-step order taught on /learn/explainers/sp-800-37/ is SP 800-37 Rev. 2: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. ISCM supports the Monitor theme and can inform an ongoing authorization decision. Running monitors is not those seven steps finished.

SP 800-30 Rev. 1 (/learn/explainers/sp-800-30/) is guidance for conducting risk assessments. The steps there are prepare, conduct, communicate, and maintain. That is assessment-process literacy. ISCM is ongoing strategy and program literacy. Related risk vocabulary, different object. SP 800-53 (/learn/explainers/sp-800-53/ and /reference/frameworks/nist-sp-800-53-r5/) is a control catalog. SP 800-137 says many technical controls are candidates for automated monitoring, and that management and operational controls still need assessment when a tool cannot watch them. A catalog is not an ISCM program.

FedRAMP (/learn/explainers/fedramp/) is a cloud Authorization reuse lane for products and services that federal agencies use. Related monitoring vocabulary can show up beside that lane. A FedRAMP package is not this publication finished. FISMA (/learn/explainers/fisma/) is the statutory backdrop for federal agency information security management. The SP 800-137 authority section cites that backdrop. FISMA is context, not this publication.

SP 800-137A, Assessing Information Security Continuous Monitoring (ISCM) Programs: Developing an ISCM Program Assessment, is the assessment companion for ISCM programs. Date Published May 2020. Document history stamps Final on 2020-05-21 (shown there as 05/21/20). DOI 10.6028/NIST.SP.800-137A. The official page is https://csrc.nist.gov/pubs/sp/800/137/a/final. Atlas names SP 800-137A only. There is no SP 800-137A explainer. A Planning Note on that CSRC page, dated 2021-03-31, points at NISTIR 8212. That note is not an Atlas page, and it is not homework here.

SP 800-39 is the organization-wide information security risk management publication. SP 800-30 already names it. The official page is https://csrc.nist.gov/pubs/sp/800/39/final. This page does not open an SP 800-39 explainer, and it does not open an SP 800-18 system security plan. Those publications are not Atlas lessons.

Six steps, literacy labels only

Chapter 3, and the CSRC glossary entry for the ISCM process, name six steps: define an ISCM strategy, establish an ISCM program, implement an ISCM program, analyze data and report findings, respond to findings, and review and update the ISCM strategy and program. Define is a risk-tolerance-aware strategy: visibility into assets, awareness of threats and vulnerabilities, and visibility into control effectiveness. Establish covers metrics, status monitoring frequencies, control assessment frequencies, and technical architecture themes. Implement collects the security-related information and automates where that helps, without pretending every control is automatable. Analyze and report turns collection into decision-useful status, and more data may be needed before acting. Respond mitigates, accepts, transfers or shares, or avoids or rejects, in line with risk tolerance. Review and update revisits the strategy and program when missions, systems, threats, or metrics stop fitting.

The executive summary says security architectures, operational capabilities, and monitoring processes improve and mature over time, and that the strategy and program are routinely reviewed. A dashboard without analysis and response is folklore. The strip below is literacy only. It does not assign frequencies. It does not copy Appendix D, Technologies for Enabling ISCM. Those catalogs stay in the PDF.

What SP 800-137 is not

Not a do-it-yourself ISCM worksheet, and not a metrics form used as the lesson. Not a SIEM shopping guide, and not a product tutorial. A SIEM (/reference/terms/siem/) can help collect and correlate telemetry. It is not an ISCM strategy or program by itself. Not FedRAMP homework. Not an SP 800-53 family dump. Not an SP 800-30 rewrite. Not an Atlas Authorization to Operate. Not permission to open SP 800-39 or SP 800-18 pages.

The publication says nongovernmental organizations may use it on a voluntary basis. Whether a named agency holds an Authorization, and whether a private team must run federal ISCM templates verbatim, is UNKNOWN on this page. Coverage questions escalate to counsel, the authorizing official, an assessor, or the GRC owner. Do not paste sensitive monitoring metrics or Authorization packages into Atlas.

Rewrite the one-line claim

Replace "we are RMF, continuous monitoring, FedRAMP, SIEM, and NIST compliant" with a reading sentence. We use SP 800-137 literacy for ISCM strategy and program themes (define, establish, implement, analyze and report, respond, review and update). That informs, and is not the same as, the seven RMF steps, an SP 800-30 assessment, a FedRAMP lane, or a single monitoring product.

For one system the team touches, privately name whether the live question is strategy, collection, analysis, response, or review and update, and which lane (an agency RMF, or some other lane) actually applies. Do not paste sensitive monitoring metrics into Atlas.

Continuous monitoring is not RMF finished, not FedRAMP, not a SIEM, and not an always authorized badge

Teaching table only. It does not assign an Authorization to Operate, a FedRAMP package, a SIEM deployment, or a score.

Six phrases people fold into one monitoring badge. Not an Authorization, and not a product.
Phrase people sayLiteracy correction
We do continuous monitoring, so RMF is doneISCM supports Monitor and ongoing risk decisions. The seven RMF steps are a broader process. Atlas card: /learn/explainers/sp-800-37/.
Continuous monitoring = FedRAMP packageFedRAMP is a cloud Authorization reuse lane. Related vocabulary, different object. Atlas card: /learn/explainers/fedramp/.
We bought a SIEM, so ISCM is doneA SIEM can help collect and correlate telemetry. It is not an ISCM strategy or program by itself. Term: /reference/terms/siem/.
Continuous monitoring = 800-30 assessment doneSP 800-30 is assessment-process literacy. ISCM is ongoing strategy and program literacy. Do not collapse them. Atlas card: /learn/explainers/sp-800-30/.
Atlas 800-137 lesson = ATOAtlas does not issue Authorizations. Completing a lesson is not Authorized.
Continuous monitoring means always authorized / Authorize foreverMonitoring can inform ongoing authorization decisions. It is not a forever Authorization badge.

Claims to retire

A monitoring dashboard, or a SIEM logo, means RMF is complete and the system is always Authorized.

ISCM supports Monitor and ongoing risk decisions. The seven RMF steps are a broader process. A dashboard is not those steps finished, and it is not a forever Authorization.

SP 800-137, SP 800-30, FedRAMP, and SP 800-53 are the same homework.

800-137 is ISCM strategy and program guidance. 800-30 is assessment-process guidance. FedRAMP is a cloud Authorization lane. 800-53 is a control catalog. Related vocabulary, different objects.

Atlas can grant an Authorization to Operate after this lesson.

Atlas does not issue Authorizations. Completing this lesson is not Authorized.

Continuous means collection never pauses, with no discrete intervals.

The publication says continuous and ongoing mean assessment and analysis at a frequency sufficient to support risk-based decisions. Data collection still happens at discrete intervals. This page does not invent that frequency.

A private team must run federal ISCM templates verbatim.

Do not invent that coverage. Nongovernmental use is voluntary in the publication. Whether a named team must follow the templates is UNKNOWN here. Escalate to counsel, the authorizing official, an assessor, or the GRC owner.

Define, establish, implement, analyze and report, respond, review and update

Static strip from SP 800-137, Chapter 3, and the CSRC glossary entry for the ISCM process. Literacy labels only. It does not assign frequencies, and it does not copy Appendix D.

Six process steps. Not a worksheet, and not a SIEM setup.
StepOne-line literacyBoundary
Define ISCM strategyA risk-tolerance-aware strategy: visibility into assets, threats, vulnerabilities, and control effectivenessStrategy first. Not a tool list.
Establish ISCM programMetrics, status monitoring frequencies, control assessment frequencies, and technical architecture themesThemes only. This page does not set frequencies.
Implement ISCM programCollect the security-related information. Automate where it helps. Not every control is automatableCollection is not the program finished.
Analyze data and report findingsTurn collection into decision-useful status. More data may be needed before actingA dashboard without analysis is folklore.
Respond to findingsMitigate, accept, transfer or share, or avoid or reject, in line with risk toleranceA finding is not a response.
Review and updateRevisit the strategy and program when missions, systems, threats, or metrics stop fittingThe program ages. One PDF is not forever.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.