Execute the Monitor step per NIST SP 800-39 Chapter 3 Section 3.4. Risk monitoring must address (a) effectiveness of risk responses (are implemented controls and other responses achieving intended risk reduction), (b) changes to information systems and operating environments (changes to threat landscape + technology stack + mission + organisation + dependencies), (c) verification of compliance with risk decisions (are accepted-risk conditions still valid + are control selections still appropriate), (d) continuous monitoring strategy aligned with NIST SP 800-137 for information security continuous monitoring, (e) updates to risk posture and reporting to Risk Executive Function + Authorising Officials + Senior Leadership at appropriate cadence, (f) reassessment triggers (significant change + incident + new threat intelligence + control failure + annual cycle). Monitor outputs feed back into Frame (revising risk frame), Assess (refreshing assessments), and Respond (revisiting responses) creating the closed risk-management loop.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.