Continuous Authorization and Monitoring

  • Release version: Yokohama
  • Updated January 30, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Continuous Authorization and Monitoring

    Continuous Authorization and Monitoring (CAM) automates the seven-step NIST Risk Management Framework (RMF) process to help organizations make informed security decisions. This framework, mandated for US federal agencies, enables companies to identify and mitigate risks to their infrastructure effectively.

    Show full answer Show less

    The CAM application standardizes and streamlines RMF implementation within ServiceNow, allowing for continuous compliance monitoring and security posture management.

    Key Features

    • RMF Step Automation: Supports all seven RMF steps, from preparation through control implementation, assessment, and ongoing monitoring.
    • Prepare: Configure authorization boundaries, control overlays, information types, and authorization packages.
    • Categorize: Define system criticality and sensitivity based on potential worst-case scenarios.
    • Select Controls: Choose baseline security controls after impact levels are approved.
    • Implement Controls: Execute control actions and implementations.
    • Assess and Manage: Evaluate internal and external controls, generate Plans of Action and Milestones (POA&M), and handle change requests and vulnerabilities.
    • Built-in Assessment Objectives: Includes NIST 800-53A assessment objectives mapped to revision 5 controls for thorough evaluation.
    • CAM Workspace: Centralized interface for continuous monitoring and management of RMF compliance and security policy adherence.
    • Reference Materials: Detailed documentation on tables, properties, forms, and roles installed with CAM for easier configuration and use.
    • Subscription and Activation: The CAM plugin requires a separate subscription and activation within ServiceNow.

    Practical Considerations for ServiceNow Customers

    • The CAM application is available for download from the ServiceNow Store; follow the provided checklist for configuration and setup.
    • Use the CAM Workspace to maintain continuous oversight of your security controls and compliance status, ensuring proactive risk management.
    • Leverage integrated NIST assessment objectives to align your security evaluations with federal standards.
    • Access reference topics and support resources including the ServiceNow Community, Known Error Portal, and Customer Service for troubleshooting and guidance.
    • Be aware that CAM requires a separate subscription, so plan licensing accordingly.

    Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.

    The video gives you an overview of the seven steps of the Risk Management Framework mandated by the US government for federal agencies that help companies to identify and eliminate risks to their infrastructure.

    Get started

    Request apps on the Store

    Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    The Continuous Authorization and Monitoring (com.sn_irm_cont_auth_monitor) plugin is available as a separate subscription and requires activation.

    Troubleshoot and get help