Executive summary
An Authority to Operate decays from the day it is signed. New vulnerabilities are published, configurations drift from STIG baselines, staff change, and the system itself changes. Continuous monitoring is the discipline that keeps the authorizing official's risk picture true between assessments.
NIST defines this discipline as Information Security Continuous Monitoring (ISCM) in SP 800-137, and NIST SP 800-37 Revision 2 makes the Monitor step the basis for ongoing authorization. DoD has pushed further: a February 2022 DoD CIO memorandum set out the path to continuous ATO (cATO) for systems that can show real-time risk visibility.
This paper argues that continuous monitoring fails when it is treated as a reporting task. It succeeds when it runs as an operating rhythm with clear owners, fixed cadences and one reconciled record.
1. Why ATOs decay
- Vulnerability drift. Every scan cycle surfaces new findings. Unworked findings become aged findings, and aged findings become conditions on the next decision.
- Configuration drift. Patches, emergency fixes and new software move hosts away from their STIG baselines.
- Undocumented change. A new interconnection or a new component that never got a security impact analysis quietly invalidates the boundary the AO approved.
- Record drift. The SSP, the POA&M and eMASS stop matching the real system. At the next assessment, the gap is the finding.
2. The operating model
We run continuous monitoring as four loops, each with one owner and one output.
| Loop | Owner and output |
|---|---|
| Vulnerability loop | ISSO with system administrators. ACAS/Nessus results triaged on the cadence your AO and component policy require; every finding either remediated, accepted or carried on the POA&M. |
| Configuration loop | System administrators, reviewed by the ISSO. STIG checklists re-run after patch cycles and major changes; deviations documented with justification. |
| Change loop | Configuration control board, with the ISSO's security impact analysis on every change before it is approved. |
| Record loop | ISSO, overseen by the ISSM. SSP, POA&M and eMASS reconciled to the scans and checklists so the record matches the system. |
3. POA&M burn-down as a management tool
A POA&M is not a parking lot. Each item needs an owner, a resource, a milestone and a scheduled completion date that someone tracks. We recommend a standing burn-down review where the ISSO reports items opened, closed and overdue, and the system owner decides on resources for the overdue ones. Trend matters more than count: a long POA&M that shrinks every cycle earns more confidence than a short one that never moves.
4. Metrics that tell the AO the truth
- Critical and high findings open past their remediation window
- STIG compliance by host class, cycle over cycle
- POA&M items opened versus closed per cycle
- Changes approved without a completed security impact analysis (target: zero)
- Days since the SSP and eMASS record were last reconciled
5. The path to ongoing authorization and cATO
Ongoing authorization is the reward for running these loops well. When the AO can see current, reliable risk data, the program no longer needs a full reauthorization on a calendar. The bar for a DoD cATO is higher still: active cyber defense, automated monitoring and a mature DevSecOps pipeline. Programs should aim for steady, reconciled monitoring first. It is the foundation every later step depends on.
6. Where to start
- Reconcile the record: one pass that makes the SSP, POA&M and eMASS match the current scans.
- Fix the cadences in writing, approved by the ISSM and AO.
- Assign one owner per loop.
- Report the five metrics every cycle.
Sources: NIST SP 800-137 · NIST SP 800-37 Rev. 2 · DoD CIO Library (cATO memorandum, February 2022)
- Continuous monitoring
- ConMon
- ISCM
- NIST SP 800-137
- Ongoing authorization
- cATO
- ACAS
- STIG
- POA&M
- eMASS
Need this done on your program?
Winston & Miller supports primes and program offices across the National Capital Region with RMF, ATO, ISSO/ISSM and CMMC work.
Request a capability statement