Assessment, Authorization, and Monitoring

A family of security controls that enable an organization to periodically assess the security controls in organizational systems to determine if the controls are effective in their application; develop and implement plans of action designed to eliminate vulnerabilities.

Resources

NIST Special Publication – An Introduction to Information Security