Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST CSWP 3

Supplemental Guidance on Ongoing Authorization: Transitioning to Near Real-Time Risk Management

Date Published: 6/3/2014

Planning Note (04/19/2019): The information in this white paper has been rolled into SP 800-37 Revision 2. Please refer to that document for current guidance.

Author(s)

Kelley Dempsey (NIST), Ron Ross (NIST), Kevin Stine (NIST)

Abstract

Keywords

information security; Office of Management and Budget; ongoing assessment; ongoing authorization; Risk Management Framework; Federal Information Security Management Act; continuous monitoring
Control Families

Assessment, Authorization and Monitoring; Risk Assessment

Documentation

Publication:
https://doi.org/10.6028/NIST.CSWP.3

Supplemental Material:
None available

Related NIST Publications:
SP 800-137
SP 800-37 Rev. 1
SP 800-39

Document History:
06/03/14: CSWP 3 (Final)