Continuous Monitoring (ConMon) is the post-authorization monitoring + reporting regime. Required activities: (a) MONTHLY vulnerability scanning + reporting via FedRAMP secure reporting portal; (b) MONTHLY POA&M update; (c) ANNUAL SECURITY ASSESSMENT by a 3PAO covering subset of NIST 800-53 controls (full assessment every 3 years on re-authorization); (d) QUARTERLY operating-system + database + web-application vulnerability scans; (e) HIGH-IMPACT VULNERABILITY remediation within 30 days; MODERATE within 90 days; LOW within 180 days (FedRAMP timelines per Rev 5); (f) annual penetration testing including authenticated + insider threat + external + internal + social engineering testing per FedRAMP PMO requirements; (g) annual review of the SSP + ConMon Plan + IRP + Contingency Plan + other authorization-package documents. SIGNIFICANT CHANGE REQUEST (SCR) workflow: CSPs must submit an SCR for any significant change to the system architecture / boundary / data flows / cryptographic implementation / personnel responsibilities / 3rd-party-service-providers / etc.; the PMO reviews + approves before the change is implemented + may require re-assessment by the 3PAO.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.