Execute the Monitor step per NIST SP 800-37 Rev 2 Chapter 3 Step 7. Maintain ongoing situational awareness of the security and privacy posture of the system to support risk management decisions. Tasks include (M-1) monitor system and environment changes (configuration drift + boundary changes + dependency changes + threat changes), (M-2) ongoing control assessments per the continuous monitoring strategy, (M-3) ongoing risk response (re-categorisation + re-selection + re-implementation + re-assessment as posture changes), (M-4) authorisation package updates with current state, (M-5) security and privacy reporting (dashboards + status reports + incident impact on authorisation), (M-6) ongoing authorisation (re-authorise based on continuous evidence rather than calendar). NIST SP 800-137 (Information Security Continuous Monitoring) provides the operational guidance for this step.
What else in your programme already covers this
This control maps to 123 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders