# FISMA & Continuous Monitoring Fundamentals Course

Canonical URL: <https://www.graduateschool.edu/courses/fisma-and-continuous-monitoring-fundamentals>

## Overview

An authorization to operate marks a beginning, not an ending. Federal systems have to be watched continuously, with weaknesses tracked and risk reported up to leadership on a standing basis. This intermediate course pairs the statutory accountability FISMA establishes with the day-to-day practice of Information Security Continuous Monitoring as laid out in NIST SP 800-137.

Participants design an ISCM strategy, put in place the asset, configuration, and vulnerability visibility that monitoring rests on, work findings through POA&Ms, and build the metrics and reporting that make ongoing authorization possible. A capstone brings those pieces together into a functioning continuous monitoring program.

## What you'll learn

- Explain how FISMA assigns accountability and structures oversight
- Design an ISCM strategy that aligns to NIST SP 800-137
- Put asset, configuration, and vulnerability visibility in place
- Keep control assessment and supporting evidence current
- Produce security metrics and risk reporting aimed at leadership
- Work findings and POA&Ms in priority order, driven by risk
- Describe ongoing authorization and how an ISCM program gets evaluated

## Prerequisites

RMF Foundations or equivalent RMF familiarity recommended.

## Curriculum

#### Module 1: FISMA Governance, Accountability, and Risk Oversight

- Examine the statutory foundation of FISMA and the roles responsible for cybersecurity governance, accountability, and risk oversight.

#### Module 2: Designing an ISCM Strategy

- Develop an information security continuous monitoring strategy aligned with NIST Special Publication 800-137.

#### Module 3: Asset, Configuration, and Vulnerability Visibility

- Review the asset, configuration, and vulnerability data needed to support effective continuous monitoring.

#### Module 4: Control Monitoring, Assessment, and Evidence Management

- Maintain current control assessments and supporting evidence throughout the system lifecycle.

#### Module 5: Security Metrics, Analysis, and Risk Reporting

- Convert monitoring data into meaningful security metrics, analysis, and risk reporting for decision-makers.

#### Module 6: Findings, POA&Ms, and Risk-Based Response

- Manage identified weaknesses through Plans of Action and Milestones and prioritize corrective actions based on risk.

#### Module 7: Ongoing Authorization and ISCM Program Evaluation

- Explore how continuous monitoring supports ongoing authorization and evaluate the effectiveness of an ISCM program.

#### Module 8: Building a Continuous Monitoring Program Capstone

- Design an end-to-end continuous monitoring program that integrates strategy, data collection, assessment, reporting, and risk response.

## Schedule
- Jan 19, 2027 9:00am–4:30pm — Live Online
- Feb 2, 2027 9:00am–4:30pm — Live Online
- Mar 4, 2027 9:00am–4:30pm — Live Online
- Apr 27, 2027 9:00am–4:30pm — Live Online
- May 14, 2027 9:00am–4:30pm — Live Online
- Jun 21, 2027 9:00am–4:30pm — Live Online
- Jul 26, 2027 9:00am–4:30pm — Live Online

## Instructors

### Wes Bryan — Instructor

Wes Bryan resides in Gainesville, Florida, and has built his career around technology, education, and helping others understand complex subjects. He values continuous learning, clear communication, and practical problem-solving. Outside of work, Wesley enjoys running, hiking, fishing, and spending time outdoors. He also has a strong interest in music and literature, enjoys reading both fiction and nonfiction, as well as playing guitar.

### Chuck Moore — Instructor

With more than 25 years of experience in IT and cybersecurity, Chuck has built a career on a strong foundation in security, networking, help desk operations, and technical training. He has helped organizations strengthen their security posture by identifying vulnerabilities, conducting threat assessments, implementing security controls, and ensuring compliance with industry standards. Combining extensive technical expertise with a passion for education, Chuck equips professionals with the knowledge and practical skills needed to recognize risks, risks and respond effectively.

## Pricing

**Tuition:** $799
