During a routine audit of a federal system's continuous monitoring program, the auditor finds that the 'Security Control Assessment' results are three years old. What is the non-compliance violation?
Ongoing authorization relies on periodic testing to ensure controls remain effective over time.
Why this answer
NIST SP 800-37 R2 requires that security controls are monitored and assessed frequently enough to maintain an ongoing authorization.