Continuous Authorization and Monitoring
Summarize
Summary of Continuous Authorization and Monitoring
Continuous Authorization and Monitoring (CAM) leverages the seven steps of the NIST Risk Management Framework (RMF) to help organizations, particularly federal agencies, make informed decisions regarding their security posture. The CAM application automates and standardizes the RMF process within ServiceNow, enabling efficient risk identification and mitigation across your infrastructure.
Show less
Key Features
- RMF Automation: CAM guides you through the seven NIST RMF steps, from preparation to ongoing monitoring, ensuring compliance with federal security mandates.
- Step-by-Step Process:
- Prepare: Establish authorization boundaries, control overlays, and information types; create authorization packages.
- Categorize: Define the criticality or sensitivity of information systems based on worst-case scenarios.
- Select Controls: Choose baseline security controls after impact levels are approved.
- Implement Controls: Deploy selected controls and perform related actions.
- Assess and Monitor: Assess controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerabilities.
- Assessment Objectives: Includes NIST 800-53A assessment objectives mapped to revision 5 controls to facilitate control implementation and evaluation.
- CAM Workspace: Provides a centralized dashboard to continuously monitor compliance and manage security policies effectively.
- Reference Documentation: Offers detailed descriptions of tables, properties, forms, and roles installed with CAM for configuration and management.
- ServiceNow Store Integration: CAM is available as a separate subscription plugin from the ServiceNow Store, with instructions for download and activation.
Practical Application for ServiceNow Customers
By implementing CAM, ServiceNow customers can systematically align their security operations with NIST RMF standards, enabling automated risk management workflows. This ensures that security controls are properly selected, implemented, and continuously monitored to maintain compliance and reduce vulnerabilities. The centralized CAM Workspace simplifies oversight, enhancing your ability to respond to security risks proactively.
Support and Resources
- Access the ServiceNow Community for questions and shared knowledge about CAM.
- Use the Known Error Portal to find solutions to common issues.
- Contact Customer Service and Support for additional assistance.
Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.
The video gives you an overview of the seven steps of the Risk Management Framework mandated by the US government for federal agencies that help companies to identify and eliminate risks to their infrastructure.
Get started
Request apps on the Store
Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
The Continuous Authorization and Monitoring (com.sn_irm_cont_auth_monitor) plugin is available as a separate subscription and requires activation.