NIST SP 800-137 NISTSP137-7: Incident Response Integration and Ongoing Authorization
Integrate ISCM with Incident Response per Section 4.7 including: SIEM alerts feeding IR + threat hunting + playbook automation per SOAR + Continuous Adversary Emulation per MITRE Caldera or a breach and attack simulation tool. Support Ongoing Authorization per Section 4.8 + NIST SP 800-37 RMF including event-driven authorisation reviews + system risk monitoring + control effectiveness assessment + authorisation decision support + Authorisation to Operate (ATO) reviews and Type Authorizations. Apply Asset Inventory Currency monitoring including HW + SW + Cloud + IoT + OT asset discovery + classification + ownership.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 60 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.