Continuous Monitoring

Information Security Continuous Monitoring (ISCM), coupled with automation, is now the norm for enterprise operations.

6 slides · 1 min read · Domain 7

Slide 1

Review/Update

Text on this slide

Define

Respond

Continuous Monitoring

Establish

Analyze/Report

Implement

ISCM maintains ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions.

ISCM requires that the organization recognizes their information assets are exposed to security risks 24 hours per day, seven days per week, across the year (holidays and work-stoppage days included) and must plan for, resource, maintain and monitor their systems from that perspective.

Text on this slide

NIST Special Publication 800-137 provides a six-phase framework for implementing an ISCM strategy.

  • Define an ISCM strategy;
  • Establish an ISCM program;
  • Implement an ISCM program;
  • Analyze Data and Report findings;
  • Respond to findings; and
  • Review and Update the ISCM strategy and program.

The term is not used in ISO publications, but the concept is expressed in ISO/IEC 27004:2016-0 Monitoring, measurement, analysis and evaluation as "Continuous quantitative measurement of ISMS relevance."

Other frameworks, including COBIT, PCI-DSS and others also expect organizations to continuously monitor controls performance.

This is shown conceptually in the figure. You'll note that these same phases have always been a part of security operations and incident response, whether as part of the frameworks or as activities performed by security professionals. What's different now is that in the past, frameworks would suggest that these phases may overlap, or that some might occur more often than others; in ISCM, these phases are all being conducted across the day, overlapping with each other, as events raise the possibilities of new precursors and indicators.

Some of the business processes that enable ISCM include comprehensive inventories, establishment of performance metrics for controls, incident response processes and continuous process improvement activities. However, the organization must have the tools and underlying systems infrastructure to gather, analyze and report on the monitored environment.

Test this domain