workflow

Continuous Controls Monitoring (ISCM) Cycle

Run the continuous controls monitoring (ISCM) cycle: pull the current-period control metrics and score them against thresholds, triage degraded and failed controls, update the POA&M, report control health to governance, recalibrate the monitoring strategy, then classify the disposition and prepare, hand off, and archive the cycle package. Each interval runs as one workflow instance attached to the existing Process item that represents the ISCM / continuous-controls-monitoring program (process_type = security_process) — enrich that program record every cycle, never create a duplicate. The monitored control set is the existing Control items (Control.frequency doubles as the monitoring cadence, Control.control_owner as the accountable owner) and the POA&M is the existing Issue register (issue_type = deficiency, source = self_assessment); metric definitions and pass/degraded/fail threshold bands have no native field, so they live in the ISCM strategy document carried on the anchor Process item. The cycle produces the control-health scorecard, the reconciled POA&M, the control-health / security-status report, and the recalibrated ISCM strategy. In scope: the recurring NIST 800-137 monitoring loop — metric collection, threshold comparison, triage, POA&M maintenance, security-status reporting, and monitoring-strategy tuning for the controls under continuous monitoring. Out of scope: formal security control assessment and driving gap remediation to closure, which is owned by the downstream Security Control Assessment & POA&M Remediation workflow that consumes this cycle's handoff package. No upstream workflow feeds this one; it is triggered by the arrival of the monitoring interval.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • risk-management
domains
  • controls
standards
  • nist-800-53
  • nist-csf-2
sourceTemplateId
workflow-library:controls-continuous-controls-monitoring-iscm
releaseId
sha256:c1eba4819d732a63c86422514455ba1cffacc57cfca35373d63457d0e5694c14
canonicalUrl
https://workflow-library.com/all/?w=controls-continuous-controls-monitoring-iscm
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-LOG-04
    • UC-AUDIT-21
    • UC-RISK-14
    • UC-RISK-13
    • UC-GOV-33
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:c1eba4819d732a63c86422514455ba1cffacc57cfca35373d63457d0e5694c14

            Connections