Execute the Monitor step per NIST SP 800-39 Chapter 3 Section 3.4. Risk monitoring must address (a) effectiveness of risk responses (are implemented controls and other responses achieving intended risk reduction), (b) changes to information systems and operating environments (changes to threat landscape + technology stack + mission + organisation + dependencies), (c) verification of compliance with risk decisions (are accepted-risk conditions still valid + are control selections still appropriate), (d) continuous monitoring strategy aligned with NIST SP 800-137 for information security continuous monitoring, (e) updates to risk posture and reporting to Risk Executive Function + Authorising Officials + Senior Leadership at appropriate cadence, (f) reassessment triggers (significant change + incident + new threat intelligence + control failure + annual cycle). Monitor outputs feed back into Frame (revising risk frame), Assess (refreshing assessments), and Respond (revisiting responses) creating the closed risk-management loop.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 98 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders