An ATO isn’t the finish line. Under RMF, Step 7 (Monitor) is where the system lives for the rest of its life. A simple, repeatable monthly routine, built on scans, POA&M updates, change review and honest reporting, keeps the authorization valid and avoids the scramble before reauthorization.
Who this is for
ISSMs and ISSOs responsible for systems after authorization, and program managers who want to know what “good” continuous monitoring (ConMon) looks like.
Why ConMon slips
The ATO team moves on, the system changes, scans pile up, and POA&M dates quietly pass. A year later the package no longer describes the real system. Ongoing authorization and continuous ATO (cATO) approaches only work if monitoring is real.
A practical cadence
| How often | What to do |
|---|---|
| Weekly | Review vulnerability scan results and new critical findings; check audit log alerts |
| Monthly | Update the POA&M (close, re-date, or escalate items); reconcile the asset inventory against scans; review STIG compliance changes; brief the system owner |
| On every change | Run a security impact analysis before significant changes; update the boundary, diagram and inventory |
| Quarterly | Review accounts and privileges; spot-check a set of controls with fresh evidence; review interconnection agreements |
| Annually | Assess a portion of controls per the ConMon strategy; test the contingency and incident response plans; review the risk assessment |
Your organization’s ConMon strategy and AO set the official frequencies; use this as a starting template.
Five habits that keep an ATO healthy
- Treat the POA&M as a living schedule. A missed date without an explanation is a finding; a re-dated item with a reason is management.
- Never let the inventory drift. The asset list, scan targets and diagram should match every month.
- Do the security impact analysis before the change, not after. It’s much cheaper to adjust a design than to undo it.
- Report risk in plain language. System owners and AOs act on clear summaries: what changed, what’s open, what’s overdue, what you need from them.
- Keep evidence as you go. If you collect evidence monthly, reauthorization becomes a review, not a rebuild.
A one-page monthly ConMon report
- Scan summary: new, closed, and overdue findings by severity
- POA&M status: items closed, re-dated (with reason), and overdue
- Changes made and security impact analyses completed
- Inventory reconciliation result
- Top three risks and the decision or support needed
Need ConMon or ISSM support?
Jumper Cyber & Risk provides cleared ISSM, ISSO and continuous monitoring support to primes and federal programs. Service-Disabled Veteran-Owned, 20+ years in DoD cybersecurity, DoD 8140 work role 722 (ISSM).
Discuss teaming: brad@jumpercyber.com or see support for primes. Related: Why ATO packages get sent back.
Sources
Leave a comment