U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

SP 800-137

Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

Date Published: September 2011


Kelley Dempsey (NIST), Nirali Chawla (PwC), L. Johnson (NIST), Ronald Johnston (DoD), Alicia Jones (BAH), Angela Orebaugh (BAH), Matthew Scholl (NIST), Kevin Stine (NIST)



Continuous monitoring; ISCM; information security; security; risk management
Control Families

Audit and Accountability; Assessment, Authorization and Monitoring; Configuration Management; Planning; Program Management; Risk Assessment


SP 800-137 (DOI)
Local Download

Supplemental Material:
Press Release (other)

Other Parts of this Publication:
SP 800-137A

Related NIST Publications:
White Paper NIST CSWP 3

Document History:
09/30/11: SP 800-137 (Final)