Keyboard keys spelling security on a red surface

RMF Continuous Monitoring Checklist: What ISSOs Do Daily, Weekly, and Monthly

Every ATO letter comes with an unwritten second document: the RMF continuous monitoring checklist your program is now expected to execute for the life of the system. The problem is that nobody hands you that checklist. NIST tells you continuous monitoring must exist, your ConMon strategy describes it in policy language, and then Monday morning arrives and you’re left translating both into actual tasks. This post is that translation — the daily, weekly, monthly, and annual rhythm that keeps a system’s authorization defensible.

I’ve written before about the mindset behind ConMon in Continuous Monitoring in RMF: What Actually Matters. This is the companion piece: the task list itself.

Daily RMF Continuous Monitoring Checklist

  • Check overnight alerts. Whatever your environment feeds you — SIEM alerts, HBSS/ESS notifications, IDS flags — triage anything new before your first meeting. Most days it’s nothing. The habit exists for the day it isn’t.
  • Scan the audit logs that matter. Not every log, every day — the high-value ones: failed privileged logons, account lockouts, new account creation, changes to security groups. Fifteen minutes, same order, every morning.
  • Review system health and backup status. A failed backup job is an availability finding waiting to be written up. Catch it the day it fails.
  • Note anything that touches your baseline. If engineering pushed a change, patched a server, or added a share overnight, capture it now for the change log — reconstructing changes weeks later during an assessment is where packages fall apart.

Weekly Tasks

  • Review vulnerability scan results. Most DoD environments run ACAS/Nessus scans on at least a weekly cadence. Read the delta, not the raw dump: what’s new since last week, what got fixed, what’s aging. New CAT I findings get escalated the day you see them.
  • Update the POA&M. Weekly, not quarterly. Milestone dates, remediation progress, evidence for closures. A POA&M touched weekly is always submission-ready; one touched quarterly is archaeology. The full workflow is in POA&M Management: How ISSOs Actually Track and Close Findings.
  • Reconcile the change log. Cross-check what the change board approved against what actually changed. Unapproved drift is a finding; catching it yourself first is the job.
  • Verify account hygiene. Departures, transfers, and role changes from the week — confirm the accounts followed. Orphaned accounts are the most reliably embarrassing assessment finding there is.

Monthly Tasks

  • Run the full account review. Every account, every privilege level, against the authorized user list — documented, dated, and filed as an artifact. This is AC-2 evidence generating itself if you let it.
  • Check STIG compliance drift. Systems drift as patches and changes land. A monthly SCAP/STIG spot-check on a rotating subset of assets catches drift before an assessor does — the process from my STIG Checklist guide applies on a monthly loop.
  • Update eMASS. Test results, closed POA&M items, refreshed artifacts. Keeping eMASS current monthly means reauthorization prep is an update, not an excavation.
  • Brief your ISSM. One page: new findings, POA&M movement, upcoming milestones, anything trending the wrong way. No surprises flowing upward.

Quarterly and Annual Tasks

  • Quarterly: review a rotating slice of your control set for continued effectiveness (your ConMon strategy usually defines the sampling), exercise a piece of the contingency plan, and re-validate that your inherited controls are still actually provided — inheritance rots silently.
  • Annually: security awareness training completion, full contingency plan test, FISMA-driven control assessments, SSP and diagram refresh, and a hard look at whether the categorization still matches what the system actually processes.

Document As You Go, Not After

The cadence above generates evidence continuously — account reviews, scan deltas, change reconciliations, ISSM briefs. File each one the day you produce it, named consistently, in the artifact structure your next assessment will use. ISSOs who do this walk into assessments with a year of dated proof that monitoring actually happened. ISSOs who don’t end up recreating history from memory, and assessors can tell the difference immediately.

Common ConMon Mistakes That Become Findings

The recurring ones: scans running but nobody reading the results (monitoring theater); POA&M milestones quietly sliding without documented justification; audit logs collected but never reviewed — AU-6 requires review, not storage; change control that exists on paper while the environment drifts; and treating ConMon as assessment prep instead of a standing operation. Every one of these is detectable by an assessor in under an hour, and every one is preventable by the checklist above.

Run your ConMon program out of two spreadsheets

The RMF ATO Checklist ($27) covers the full authorization lifecycle including the monitoring phase gates, and the POA&M Tracker ($37) is the exact weekly-review tracker this post describes — milestones, aging, evidence, and status in one place.

Final Thoughts

Continuous monitoring is the part of RMF that determines whether your ATO means anything three months after it’s signed — and with DoD’s shift toward constant-authorization models, this rhythm is only becoming more central to the ISSO role. Build the cadence, automate what your tools allow, document as you go, and the next assessment becomes a review of work already done instead of a scramble to invent it.

Related reading: If you are unsure which of these daily tasks are actually yours, see ISSO vs ISSM vs ISSE: what is the actual difference (and which pays more).

On the tooling side: If MFA gaps keep landing on your POA&M, see the YubiKey 5 NFC review for what phishing-resistant authentication actually looks like in practice.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

3 responses

  1. Continuous Monitoring in RMF: What Actually Matters (With Real-World Lessons) – RMFInsider

    […] Related reading: RMF Continuous Monitoring Checklist: Daily, Weekly, Monthly […]

  2. Best Hardware Encrypted Drives in 2026 (FIPS-Validated vs Consumer) – RMFInsider

    […] this decision as part of a control implementation, it’s worth cross-referencing your ConMon checklist and, if a gap turns up, tracking it properly in a POA&M rather than letting it sit […]

  3. Firewalla Purple SE Review: A No-Subscription Home Firewall for Security Pros – RMFInsider

    […] boundary — the same instinct that drives a lot of ConMon practice at the enterprise level. Our ConMon checklist covers that mindset in the formal RMF context if you want the parallel spelled […]

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading