Continuous Monitoring
Continuous monitoring is the practice of keeping constant, ongoing awareness of an organization's security posture, vulnerabilities, and threats rather than checking them only at scheduled intervals. It typically combines technology and process to detect security risks and compliance issues as they emerge. The goal is to support timely, informed decisions about how to manage organizational risk.
Continuous monitoring, as defined by NIST, refers to maintaining ongoing awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. In practice it is implemented through technology and processes that provide automated or highly frequent surveillance of IT systems, networks, and controls to enable rapid detection of security risks and compliance issues. Related but narrower variants include continuous security monitoring, which focuses on ongoing surveillance for security vulnerabilities, and continuous controls monitoring (CCM), which uses technology-based solutions to support automated, ongoing evaluation of the effectiveness of controls. Note that 'continuous' commonly denotes highly frequent or automated monitoring rather than literally uninterrupted observation, and specific scope, tooling, and frequency depend on organizational risk context. This entry describes the concept generally; it is a practice rather than a binding regulation, though it may be required or expected under specific frameworks, contracts, or authorization regimes. Readers should verify definitions and any applicable requirements against current authoritative sources.
Why it matters
Point-in-time assessments—annual audits, quarterly vulnerability scans, or scheduled control reviews—capture an organization's security posture only as it stood on the day of evaluation. Threats, configurations, and control effectiveness can change substantially between those checkpoints, leaving gaps during which emerging risks go undetected. Continuous monitoring addresses this limitation by maintaining ongoing awareness of information security, vulnerabilities, and threats, enabling organizations to detect security risks and compliance issues as they arise rather than discovering them retroactively.
Who it's relevant to
Inside CM
Common questions
Answers to the questions practitioners most commonly ask about CM.

