NIST SP 800-37
RMF Step 6 - Monitor

NIST SP 800-37 NISTSP37-7: RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

Execute the Monitor step per NIST SP 800-37 Rev 2 Chapter 3 Step 7. Maintain ongoing situational awareness of the security and privacy posture of the system to support risk management decisions. Tasks include (M-1) monitor system and environment changes (configuration drift + boundary changes + dependency changes + threat changes), (M-2) ongoing control assessments per the continuous monitoring strategy, (M-3) ongoing risk response (re-categorisation + re-selection + re-implementation + re-assessment as posture changes), (M-4) authorisation package updates with current state, (M-5) security and privacy reporting (dashboards + status reports + incident impact on authorisation), (M-6) ongoing authorisation (re-authorise based on continuous evidence rather than calendar). NIST SP 800-137 (Information Security Continuous Monitoring) provides the operational guidance for this step.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.