Outcome · Keep the evidence readyA government-wide services agency
Authorization evidence kept current between assessments, not rebuilt for them.
01 · Problem
What was in the way?
Security operations, vulnerability management and authorization maintenance competed for the same people across one infrastructure estate, and every emergency directive arrived on top of the annual assessment calendar rather than instead of it.
02 · Technology at work
What did the technology do?
Continuous monitoring, patch management and configuration enforcement run alongside assessment work, with logs consolidated into a SIEM to meet OMB M-21-31.
03 · Human role
Where did people keep authority?
The security team keeps system security plans and POA&M items current as the work happens, and the authorizing official decides.
04 · Result
What changed?
Evidence stays current between assessments, and three emergency directives were absorbed without moving the calendar.