Continuous Monitoring
Continuous monitoring is the automated, ongoing verification that security controls are operating — access properly restricted, encryption enforced, endpoints compliant, vendors reviewed — with drift surfaced as it happens rather than discovered during audit prep. It’s the core mechanism of every modern compliance platform.
Why it changed the category
Before continuous monitoring, compliance evidence was archaeology: teams reconstructed a year of screenshots before each audit. With it, evidence accumulates as a byproduct of controls operating, and the audit becomes a review of existing records. The catch: monitoring surfaces problems but doesn’t fix them. An alert queue nobody owns is just a well-documented list of failures — the gap between monitoring and remediation is where programs stall.
Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.
Observation Window — The observation window is the period a SOC 2 Type II report covers — typically 3 to 12 months — during which controls must demonstrably operate.
Penetration Test vs Vulnerability Scan — A vulnerability scan is automated and finds known issues; a penetration test is a human actively exploiting your defenses. Auditors and customers ask for both.