Scheduled Searches and Alerts That Satisfy Continuous Monitoring
New to how Splunk fits into compliance work? Start with How Splunk Supports Cybersecurity Evidence. Most people in federal IT have written “continuous monitoring” into a security plan before they have actually built anything that monitors continuously. So what turns a ConMon strategy from a paragraph in a document into something an assessor can verify, and what does Splunk actually need to be doing for that to hold up? The Gap Between the Policy and the Platform NIST SP 800-137 describes an Information Security Continuous Monitoring program as an ongoing awareness of risk, vulnerabilities, and threats. DoDI 8510.01 expects that awareness to feed the authorization decision on a continuing basis, not just at the three-year reassessment. The document usually gets written first. The searches that are supposed to produce that awareness get written later, if at all, and often only after an assessor asks to see one running. ...