[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-171372-105":53,"doc-detail-171372-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","fedramp-tailored-low-impact-software-as-a-service-li-saas-continuous-monitoring-guide-version-20-overview","FedRAMP Tailored Low Impact Software as a Service (LI-SaaS) Continuous Monitoring Guide - Version 2.0 - Overview","","FedRAMP Tailored Low Impact Software as a Service (LI-SaaS) Continuous Monitoring Guide defines how continuous monitoring and ongoing authorization support ongoing risk management after initial authorization. It aligns with OMB Circular A-130 Appendix I and NIST SP 800-137, explaining how Authorizing Officials use sufficient security-state information to decide whether continued operation remains acceptable. The guide sets minimum strategy and requirements for CSPs to monitor security posture changes, conduct ongoing assessment activities, and manage controls, incidents, and change control to sustain FedRAMP Tailored LI-SaaS compliance.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/fedramp-tailored-low-impact-software-as-a-service-li-saas-continuous-monitoring-guide-version-20-overview/171372/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/fedramp-tailored-low-impact-software-as-a-service-li-saas-continuous-monitoring-guide-version-20-overview/171372.png","ImageObject",442,249,{"name":88,"@type":89},"Aria","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-10-02","2026-09-01",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",8,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"What is the purpose of continuous monitoring in the FedRAMP Tailored LI-SaaS context?","Question",{"text":109,"@type":110},"Continuous monitoring maintains ongoing awareness of security, vulnerabilities, threats, and incidents so risk-based decisions can be made after initial authorization. It supports maintaining an authorization state that continues to meet FedRAMP Tailored LI-SaaS requirements.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"Which standards and authorities does the guide align with?",{"text":114,"@type":110},"The guide aligns with OMB Circular No. A-130, Appendix I, and NIST Special Publication 800-137. It also follows the FedRAMP ongoing assessment and authorization program approach for Tailored LI-SaaS.",{"name":116,"@type":107,"acceptedAnswer":117},"Who is expected to use the continuous monitoring guide?",{"text":118,"@type":110},"Cloud Service Providers (CSPs), Independent Assessors, government contractors on FedRAMP projects, and government employees working on FedRAMP projects should use the guide. Other organizations building a ConMon program may also find it useful.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},171372,1788282169,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":136,"language":137,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":138,"faqs":139,"seo_title":140,"seo_description":61,"update_tm":126,"read_time":141},2336464648322,"https://ap-avatar.wpscdn.com/avatar/2200025388227c56fec?_k=1778556882303663488","FedRAMP Tailored Low Impact\nSoftware as a Service (LI-SaaS) \u000bContinuous Monitoring Guide\nFederal Risk and Authorization Management Program\nVersion 2.0\nAugust 23, 2017\n\u000fExecutive Summary\nThe Office of Management (OMB) Circular No. A-130, Appendix I (OMB A-130), issued July 28, 2016, requires the implementation of continuous monitoring (ConMon) as a means for maintaining ongoing awareness of the information security, vulnerabilities, threats, and incidents to support the agency risk management decisions. OMB A-130 defines “ongoing authorization” as “the means for determining risk and for making risk acceptance decision subsequent to the initial authorization, taken at agreed-upon and documented frequencies in accordance with the agency’s mission or business requirements and agency risk tolerance.” OMB A-130 further defines ongoing authorization as a time-driven or event-driven authorization process whereby the Authorizing Official (AO) is provided with the necessary and sufficient information regarding the security state of the information system to determine whether the mission or business risk of continued system operation is acceptable.\nConsistent with OMB A-130 and in accordance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations, FedRAMP developed an ongoing assessment and authorization program for the purpose of maintaining the authorization of FedRAMP Tailored Low Impact Software as a Service (LI-SaaS) Cloud Service Providers (CSP).\nThis continuous monitoring guide describes the FedRAMP strategy and minimum requirements for a CSP to use once it has received a FedRAMP Authorization based on the FedRAMP Tailored \u000bLI-SaaS requirements.  CSPs must continuously monitor the cloud service offering to detect changes in the security posture of the system to enable well-informed risk-based decision making.\n\u000fDocument Revision History\n\u000f\n\u0003Table of Contents\n\u0013 TOC \\o \"1-3\" \\h \\z \\u \u0014\u0013 HYPERLINK \\l \"_Toc490669230\" \u00141.\tOverview\t\u0013 PAGEREF _Toc490669230 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669231\" \u00141.1.\tPurpose of This Document\t\u0013 PAGEREF _Toc490669231 \\h \u00142\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669232\" \u00141.2.\tContinuous Monitoring Process\t\u0013 PAGEREF _Toc490669232 \\h \u00142\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669233\" \u00142.\tContinuous Monitoring Roles And Responsibilities\t\u0013 PAGEREF _Toc490669233 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669234\" \u00142.1.\tAuthorizing Official\t\u0013 PAGEREF _Toc490669234 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669235\" \u00142.2.\tFedRAMP PMO\t\u0013 PAGEREF _Toc490669235 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669236\" \u00142.3.\tDepartment of homeland security (DHS)\t\u0013 PAGEREF _Toc490669236 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669237\" \u00142.4.\tIndependent Security Assessment\t\u0013 PAGEREF _Toc490669237 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669238\" \u00142.5.\tFedRAMP Tailored LI-SaaS CSP\t\u0013 PAGEREF _Toc490669238 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669239\" \u00143.\tContinuous Monitoring Process\t\u0013 PAGEREF _Toc490669239 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669240\" \u00143.1.\tOperational Visibility\t\u0013 PAGEREF _Toc490669240 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669241\" \u00143.2.\tOngoing Continuous Monitoring Requirements\t\u0013 PAGEREF _Toc490669241 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669242\" \u00143.3.\tAnnual Continuous Monitoring Requirements\t\u0013 PAGEREF _Toc490669242 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669243\" \u00143.4.\tChange Control\t\u0013 PAGEREF _Toc490669243 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669244\" \u00143.5.\tIncident Response\t\u0013 PAGEREF _Toc490669244 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669245\" \u00144.\tAuthorizing Official (AO) Continuous Monitoring Analysis Process\t\u0013 PAGEREF _Toc490669245 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490669246\" \u00145.\tAppendix A - Control Frequencies\t\u0013 PAGEREF _Toc490669246 \\h \u001411\u0015\u0015\n\u0015\u0004\nList of Figures & Tables\n\u0013 TOC \\f t \\h \\z \\t \"Caption,1\" \\c \"Figure\" \u0014\u0013 HYPERLINK \\l \"_Toc490665531\" \u0014Figure 1 – NIST Special Publication 800-137 ConMon Process\t\u0013 PAGEREF _Toc490665531 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc490665532\" \u0014Table 3-1 – Criteria for AO Selection of Additional T","cbCairVfdUQ4FMSh","https://ap.wps.com/l/cbCairVfdUQ4FMSh","docx",338958,19,"English","# Overview\n## Purpose of This Document\n## Continuous Monitoring Process\n# Continuous Monitoring Roles And Responsibilities\n## Authorizing Official\n## FedRAMP PMO\n## Department of Homeland Security (DHS)\n## Independent Security Assessment\n## FedRAMP Tailored LI-SaaS CSP\n# Continuous Monitoring Process\n## Operational Visibility\n## Ongoing Continuous Monitoring Requirements\n## Annual Continuous Monitoring Requirements\n## Change Control\n## Incident Response\n# Authorizing Official (AO) Continuous Monitoring Analysis Process\n# Appendix A - Control Frequencies","[{\"question\":\"What is the purpose of continuous monitoring in the FedRAMP Tailored LI-SaaS context?\",\"answer\":\"Continuous monitoring maintains ongoing awareness of security, vulnerabilities, threats, and incidents so risk-based decisions can be made after initial authorization. It supports maintaining an authorization state that continues to meet FedRAMP Tailored LI-SaaS requirements.\"},{\"question\":\"Which standards and authorities does the guide align with?\",\"answer\":\"The guide aligns with OMB Circular No. A-130, Appendix I, and NIST Special Publication 800-137. It also follows the FedRAMP ongoing assessment and authorization program approach for Tailored LI-SaaS.\"},{\"question\":\"Who is expected to use the continuous monitoring guide?\",\"answer\":\"Cloud Service Providers (CSPs), Independent Assessors, government contractors on FedRAMP projects, and government employees working on FedRAMP projects should use the guide. Other organizations building a ConMon program may also find it useful.\"}]","FedRAMP Tailored Low Impact Software as a Service (LI-SaaS) Continuous Monitoring Guide - Version 2.0 - Overview | DOCX",7]