# FISMA & Continuous Monitoring Fundamentals (Self-Paced) (Coming Soon)

Canonical URL: <https://www.graduateschool.edu/courses/fisma-and-continuous-monitoring-fundamentals-self-paced>

## Overview

An authorization to operate is not the finish line. Federal systems must be monitored continuously, with weaknesses tracked and risk reported to leadership on an ongoing basis. This intermediate course covers the statutory accountability FISMA establishes and the practical work of Information Security Continuous Monitoring as described in NIST SP 800-137. 

Learners design an ISCM strategy, establish the asset, configuration, and vulnerability visibility that monitoring depends on, manage findings through POA&Ms, and build the metrics and reporting that support ongoing authorization. The capstone assembles these pieces into a working continuous monitoring program.

## What you'll learn

- Explain FISMA accountability and oversight structures
- Design an ISCM strategy aligned to NIST SP 800-137
- Establish asset, configuration, and vulnerability visibility
- Manage ongoing control assessment and evidence
- Build security metrics and risk reporting for leadership
- Manage findings and POA&Ms with a risk-based approach
- Describe ongoing authorization and how to evaluate an ISCM program

## Prerequisites

RMF Foundations or equivalent RMF familiarity recommended.

## Curriculum

#### Module 1: FISMA Governance, Accountability, and Risk Oversight

- Examine the statutory foundation of FISMA and the roles responsible for cybersecurity governance, accountability, and risk oversight.

#### Module 2: Designing an ISCM Strategy

- Develop an information security continuous monitoring strategy aligned with NIST Special Publication 800-137.

#### Module 3: Asset, Configuration, and Vulnerability Visibility

- Review the asset, configuration, and vulnerability data needed to support effective continuous monitoring.

#### Module 4: Control Monitoring, Assessment, and Evidence Management

- Maintain current control assessments and supporting evidence throughout the system lifecycle.

#### Module 5: Security Metrics, Analysis, and Risk Reporting

- Convert monitoring data into meaningful security metrics, analysis, and risk reporting for decision-makers.

#### Module 6: Findings, POA&Ms, and Risk-Based Response

- Manage identified weaknesses through Plans of Action and Milestones and prioritize corrective actions based on risk.

#### Module 7: Ongoing Authorization and ISCM Program Evaluation

- Explore how continuous monitoring supports ongoing authorization and evaluate the effectiveness of an ISCM program.

#### Module 8: Building a Continuous Monitoring Program Capstone

- Design an end-to-end continuous monitoring program that integrates strategy, data collection, assessment, reporting, and risk response.

## Instructors

### Wes Bryan — Instructor

Wes Bryan resides in Gainesville, Florida, and has built his career around technology, education, and helping others understand complex subjects. He values continuous learning, clear communication, and practical problem-solving. Outside of work, Wesley enjoys running, hiking, fishing, and spending time outdoors. He also has a strong interest in music and literature, enjoys reading both fiction and nonfiction, as well as playing guitar.

## Pricing

**Tuition:** $799
