logo

NJP

GRC: Continuous Authorization and Monitoring

GRC: Continuous Authorization and Monitoring

by Service-now.com

Simplify NIST Risk Management Framework implemention

0 installs 0 reviews v22.3.3 Scoped Application Free-ish (consumes 20 tables) 20 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 25 -25
159 days of no change
2025-11-18 24 +1
27 days of no change
2025-10-21 23 +1
11 days of no change
2025-10-09 22 +1
51 days of no change
2025-08-18 21 +1
18 days of no change
2025-07-30 20 +1
2025-07-29 19 +1
34 days of no change
2025-06-24 18 +1
46 days of no change
2025-05-08 17 +1
10 days of no change
2025-04-27 16 +1
47 days of no change
2025-03-10 15 +1
12 days of no change
2025-02-25 14 +1
5 days of no change
2025-02-19 13 +1

About

The ServiceNow® Continuous Authorization and Monitoring (CAM) application helps government agencies, contractors, critical infrastructure entities, and other high-assurance organizations manage compliance with cyber risk management frameworks.

CAM supports a broad range of frameworks and standards, including the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), Defense Federal Acquisition Regulation Supplement/NIST 800-171 (DFARS), FedRAMP, ISO 31000, and other high-maturity standards.

CAM streamlines the entire risk management lifecycle, reducing manual effort, improving collaboration across functional teams, and adapting to your organization's processes. The application also automates key tasks across authorization boundary management, impact assessments, system categorization, control implementation, audits, Plans of Action and Milestones (POA&Ms), artifact management, attestations, continuous monitoring, and ongoing authorization.

Key Features

- Manage authorization boundaries with deep integration into CMDB.
- Manage and assign roles such as ISSO, ISSM, System Owner, Security Control Assessors, Information Owner, and key stakeholders.
- Attach key artifacts, such as the data flow diagram and the network diagram.
- Perform impact analysis within the platform with automated system categorization.
- Automatically select baseline controls with selection overrides.
- Manage control overlays with individual control tailoring and reasons for control exceptions.
- Define and inherit common controls across authorization boundaries with full visibility of those controls, their owners, and current states.
- Automatically generate issues and findings based on automated or manual indicators, or attestations.
- Receive attestation responses and artifacts within the platform without resorting to email and spreadsheets.
- Use indicators to define acceptable or unacceptable data conditions for true continuous monitoring.
- Create assessment engagements and test plans, and issue assessment tasks to control assessors.
- Create and manage Plans of Action and Milestones (POA&Ms) and drive related work tasks and subtasks across functional teams without leaving the platform.
- Gain visibility into the work completion status and timeliness of POA&Ms in progress before they are overdue.
- Automatically generate System Security Plans (SSPs) with up-to-date ground truth.
- Continuously monitor the state of compliance and authorization of your programs and missions.

Version History (9)
v22.3.3 2026-06-16 16:27:03
Changed This release includes the following changes: CAM email notifications now include references to records in the workspace. Fixed This relea...
v22.0.2 2026-03-12 15:44:38
Fixes: Security bugs. Resolved the visibility of Vulnerable item widget even without the security plugin in the Overview tab. Resolved Access Rest...
v21.1.1 2025-12-11 12:47:27
New: Relationships between boundaries can now be created. Hierarchy of boundaries is now supported. Adding a "Dynamic Filter" checkbox for boundar...
v21.0.1 2025-07-31 15:53:32
New: Enhanced security on authorization boundary, authorization package,  acceptance task, milestone task, information type, system element t...
v20.2.1 2025-07-10 14:55:22
Fixed: Resolved known defects impacting core functionality and user experience.  
v20.2.0 2025-06-06 01:31:37
Fixed: Enhanced security by creating Query range ACLs across multiple tables.
v20.1.0 2025-05-01 18:46:34
Fixed: Security and minor defect fixes.
v20.0.3 2025-01-30 15:34:34
Changed: Add button in Baseline control related list now shows all control objectives instead of NIST rev5/rev4 control objectives.  
v19.1.1 2024-11-07 16:03:25
Changed Security fixes Fixed Impact of NIST R5 control objectives are updated as per NIST standards. Implementation field made editable in Rev...
ID: 73374a5107301010bbc77f04a9d300e5 · Published: Jun 2026 · Updated: Sep 09, 2026