U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

White Paper

Supplemental Guidance on Ongoing Authorization: Transitioning to Near Real-Time Risk Management

Date Published: 6/3/2014

Planning Note (4/19/2019): The information in this white paper has been rolled into SP 800-37 Revision 2. Please refer to that document for current guidance.


Kelley Dempsey (NIST), Ron Ross (NIST), Kevin Stine (NIST)



Federal Information Security Management Act; information security; Office of Management and Budget; ongoing assessment; ongoing authorization; continuous monitoring; Risk Management Framework
Control Families

Risk Assessment; Assessment, Authorization and Monitoring


White Paper (DOI)

Supplemental Material:
None available

Document History:
06/03/14: White Paper