A process to:
• Define an ISCM strategy;
• Establish an ISCM program;
• Implement an ISCM program;
• Analyze data and Report findings;
• Respond to findings; and
• Review and Update the ISCM strategy and program.
Source(s):
CNSSI 4009-2015
from
NIST SP 800-137
NIST SP 800-137
under Information Security Continuous Monitoring (ISCM) Process