Continuous monitoring vs continuous authorization
Continuous monitoring is an evidence practice a program runs. Continuous authorization is a posture an AO grants on the strength of it. You can do the first without the second, and you cannot get the second without the first.
These two phrases get used as synonyms in vendor material and they are not the same thing. The difference matters when you are deciding what to build toward.
Continuous monitoring
An evidence practice. You are running it if security-relevant change in the system produces signal into the authorization record on an ongoing basis rather than at review time: scan results arriving from the pipeline, inventory snapshots compared for drift, STIG applicability re-ranked when the technology stack moves, evidence continuity tracked, findings flowing into POA&M.
You control this entirely. It requires nobody’s permission. And it is worth doing on its own merits, because it is the difference between knowing your posture and reconstructing it.
Continuous authorization
An authorization posture. Your AO has agreed that, on the strength of your monitoring and process maturity, changes within an agreed envelope do not require a fresh authorization decision.
You do not control this. It is granted, it is scoped, and it is conditional on the monitoring actually being real. Programs that pursue it as a goal in itself tend to be disappointed, because the prerequisite is the boring work in the first section.
Why the confusion is expensive
Because it leads programs to buy for the wrong outcome.
A tool sold on “continuous ATO” that automates document generation has not given you continuous monitoring — it has given you a faster way to produce a package. Meanwhile the questions an AO will actually ask before granting a continuous authorization are all monitoring questions:
- How do you know when the system changed?
- How do you know what that change affected?
- How do you know your evidence still describes the system?
- Can you show me the assessment history, and what each assessment was performed against?
- What can change without a human approving it?
Notice that none of these are about how quickly you can generate an SSP.
What to build toward
Build the monitoring. Specifically, build the part that turns change into scoped work:
- A versioned record of the system, so change is detectable rather than reported.
- Derived impact, so a change produces a bounded set of controls to re-examine.
- Assessments bound to what they assessed, so history stays meaningful.
- Evidence bound to what it supports, so reuse is possible.
- An audit record that resists rewriting, so the whole thing is checkable.
If you have those five, the continuous authorization conversation with your AO is a conversation about evidence you already have. If you do not, it is a conversation about intentions.