Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-137A

Assessing Information Security Continuous Monitoring (ISCM) Programs: Developing an ISCM Program Assessment

Date Published: May 2020

Planning Note (03/31/2021):

NISTIR 8212, An Information Security Continuous Monitoring Program Assessment, provides an operational approach to the assessment of an organization’s ISCM program using ISCMAxa free, publicly available working implementation of the ISCM program assessment described in NIST SP 800-137A.


Kelley Dempsey (NIST), Victoria Pillitteri (NIST), Chad Baer (CISA), Robert Niemeyer (MITRE), Ron Rudman (MITRE), Susan Urban (MITRE)



assessment; assessment element; assessment methodology; assessment procedure; continuous monitoring; information security continuous monitoring; ISCM program; ISCM program assessment
Control Families

None selected


Download URL

Supplemental Material:
Element Catalog for SP 800-137A (xlsx)

Publication Parts:
SP 800-137

Related NIST Publications:
IR 8212

Document History:
01/13/20: SP 800-137A (Draft)
05/21/20: SP 800-137A (Final)