NIST SP 800-137
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
IR and Authorisation
Integrate ISCM with Incident Response per Section 4.7 including: SIEM alerts feeding IR + threat hunting + playbook automation per SOAR (Cortex XSOAR + Splunk SOAR + Tines + Swimlane + Microsoft Sentinel Playbooks) + Continuous Adversary Emulation per MITRE Caldera or AttackIQ. Support Ongoing Authorization per Section 4.8 + NIST SP 800-37 RMF including event-driven authorisation reviews + system risk monitoring + control effectiveness assessment + authorisation decision support + Authorisation to Operate (ATO) reviews and Type Authorizations. Apply Asset Inventory Currency monitoring including HW + SW + Cloud + IoT + OT asset discovery + classification + ownership.
- SIEM-IR integration
- SOAR playbooks
- Ongoing authorisation evidence
- Asset inventory currency
- Threat hunting reports
- Disconnected IR
- No SOAR
- No ongoing authorisation
- Stale asset inventory
ISCM Strategy
Establish Information Security Continuous Monitoring (ISCM) per NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations published September 2011 + companion to NIST SP 800-37 Risk Management Framework + NIST SP 800-53/53A controls + NIST Privacy Framework continuous monitoring. Define ISCM strategy per Section 3.1 covering organisational and system-level objectives + assumptions + constraints + risk tolerance. Conduct security control volatility assessment to identify rapidly-changing controls requiring more frequent monitoring (vulnerability + patching + configuration vs stable controls like physical access). Establish governance structure with Authorising Official + System Owner + ISSO + ISCM Manager.
- ISCM strategy document
- Volatility assessment
- Roles and responsibilities
- Annual strategy review
- AO sign-off
- No ISCM strategy
- Missing volatility assessment
- Unclear roles
- Stale strategy
Malware and Access Monitoring
Monitor malware per Section 4.4 including signature-based AV + behavioral EDR + sandboxing + threat intel feed integration + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs). Monitor identity and access per Section 4.5 including failed authentications + anomalous access + privilege escalations + after-hours access + UEBA (User and Entity Behavior Analytics) + impossible travel + dormant account use. Monitor network boundary per Section 4.6 including firewall logs + IDS/IPS + DLP + DNS + proxy + VPN + zero trust network access (ZTNA) + east-west traffic + microsegmentation effectiveness.
- EDR coverage
- UEBA deployment
- IDS/IPS metrics
- DLP alerts
- ZTNA enforcement
- Gaps in EDR
- No UEBA
- Network blind spots
- Weak DLP
Metrics and Frequencies
Define ISCM metrics per Section 3.2 covering security control effectiveness + system + organizational metrics + leading and lagging indicators + Cyber-Resilience metrics + KPIs (Mean Time to Detect MTTD + Mean Time to Respond MTTR + Mean Time to Remediate MTTR + Mean Time Between Failures MTBF). Establish monitoring and assessment frequencies based on control volatility + system categorisation + risk tolerance + threat environment + resource constraints. Apply continuous (real-time + near-real-time) for high-volatility controls + periodic (daily/weekly/monthly/quarterly) for lower volatility + annual for stable controls.
- Metrics framework
- KPI dashboard
- Frequency matrix per control
- Quarterly review
- Continuous monitoring evidence
- No metrics
- Missing KPIs
- No frequency rationale
- Stale dashboards
Programme Management
Conduct ISCM Programme Review per Section 4.9 annually + capability maturity assessment + gap analysis + improvement planning aligned with NIST CSF 2.0 implementation tiers. Train workforce for ISCM per Section 4.10 including ISCM concepts + tool usage + analytical skills + interpretation of metrics + role-based training. Apply Third-Party Monitoring Coverage per Section 4.11 covering MSSPs + MDRs + cloud security providers + outsourced SOC + sub-processor monitoring + SCRM + supply chain risk management per NIST SP 800-161 + ICT SCRM + FedRAMP + StateRAMP + DoD CMMC.
- Annual programme review
- Maturity assessment
- Training programme
- Third-party monitoring coverage
- MSSP/MDR SLAs
- No programme review
- Missing training
- Third-party gaps
- Weak SCRM
Reporting and Risk Scoring
Provide security status reporting per Section 3.6 to System Owners + ISSO + AO + CISO + senior leadership. Apply risk score aggregation including: vulnerability scoring (CVSS v4.0 + EPSS + KEV catalog) + asset criticality scoring + threat intelligence overlay + business impact analysis. Use ATT&CK MITRE coverage scoring + NIST Cybersecurity Framework profile scoring + RMF system risk score per NIST SP 800-39 + Continuous Diagnostics and Mitigation (CDM) Federal Dashboard. Apply Federal Information Security Modernization Act (FISMA) reporting + OMB CyberStat reviews + annual FISMA report.
- Security dashboards
- Risk scoring methodology
- CDM Federal Dashboard
- Annual FISMA report
- Monthly executive reports
- No reporting
- Missing risk scoring
- No FISMA report
- No CDM
Technical Architecture
Architect ISCM technology stack per Section 3.3 + 3.4 including: SIEM (Splunk + QRadar + Elastic Security + Sentinel + Chronicle + Sumo Logic) + EDR/XDR (CrowdStrike + SentinelOne + Microsoft Defender + Palo Alto Cortex) + vulnerability scanners (Tenable + Qualys + Rapid7) + configuration management (Ansible + Puppet + Chef + Salt + Microsoft Configuration Manager) + identity governance (SailPoint + Saviynt + Okta + Ping) + GRC platforms (ServiceNow + RSA Archer + LogicGate + AuditBoard) + integration via APIs + SCAP + OSCAL + ASCII-Armor + STIX/TAXII. Apply data collection automation per Section 3.5 minimising manual data collection + leveraging configuration and vulnerability data + CMDB integration.
- ISCM architecture
- Tool inventory
- Automation rate metrics
- SCAP/OSCAL integration
- API integration
- Manual monitoring
- Tool silos
- No automation
- Missing API integration
Vulnerability and Configuration
Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + Tenable + Qualys + Rapid7 + open-source OpenVAS. Monitor patch management status per Section 4.2 including Critical 7 days + High 30 days + Medium 90 days + emergency patching processes + WSUS + SCCM + JAMF + automated patching pipelines. Monitor configuration status per Section 4.3 including baseline compliance per CIS Benchmarks + DISA STIGs + custom baselines + drift detection + configuration management database (CMDB) currency.
- Vulnerability scans + KPIs
- Patch SLA tracking
- Configuration baseline compliance
- CMDB currency
- Drift detection alerts
- Patches exceed SLA
- No baseline
- Drift not detected
- Stale CMDB
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-137 framework page.