Is it the information system owner that is responsible for the continuous monitoring phase? or just the responsible party but others may be assign to handle the phase?
The System Owner, though listed as the responsible party in NIST 800-37, does not do all the leg work in this Phase. The ISSO updates implementation statements if need be and uploads artifacts for the Assessor to assess. The Assessor assesses the controls, reviews the implementation statement and passes or fails the control.
The ISSO then briefs the System Owner on the status of the continuous monitoring (Sir/Madam, this is how many controls failed, this is how many passed). System Owner approves is briefed before, during and after continuous monitoring and signs any documents needed
What's new in the world of Cybersecurity?