Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8212

ISCMA: An Information Security Continuous Monitoring Program Assessment

Date Published: March 2021

Planning Note (03/31/2021):

The ISCMAx tool available under Supplemental Material is a macro-enabled Microsoft Excel application that runs on Windows-based systems only. ISCMAx is not intended to be a production-level product.


Kelley Dempsey (NIST), Victoria Pillitteri (NIST), Chad Baer (DHS), Ron Rudman (MITRE), Robert Niemeyer (MITRE), Susan Urban (MITRE)



assessment; continuous monitoring; information security continuous monitoring; information security continuous monitoring assessment; ISCM; ISCMA; ISCMAx
Control Families

None selected


Download URL

Supplemental Material:
ISCMAx: Recommended Judgments (xlsx)
ISCMAx: Alternate Judgments (xlsx)

Related NIST Publications:
SP 800-137A

Document History:
10/01/20: IR 8212 (Draft)
03/31/21: IR 8212 (Final)