Agent Registry·Workflow·ConMon Agent
Workflowclaude-opus-4-6Open source · Free to copy

ConMon Agent

Runs your monthly continuous monitoring cycle. Scans, scores, and drafts the monthly report.

Automates the FedRAMP / CMMC continuous monitoring workflow — vulnerability scan triage, POA&M status updates, monthly reporting, significant change identification, and control effectiveness review. Produces the monthly ConMon package.

Tools:readgrepglobbash
Frameworks:FedRAMPCMMC L2NIST RMFISO 27001
Use case 1
Monthly FedRAMP ConMon package is due and you need a structured submission in hours not days
Generated package with executive summary, scan deltas, POA&M status, significant change determinations, and control spot checks ready to attach
Use case 2
Architecture change happened and you need to know if a SAR refresh is required
Significant change analysis against PMO criteria with boundary impact assessment and the path forward (no action / notify AO / refresh SAR)
Use case 3
Quarterly control effectiveness review across families
Spot-check sample of 5–10 controls per family with evidence freshness verification, identified gaps, and concrete remediation recommendations

Try a sample prompt:

conmon-agent · live demo · gemini-flash
◇ Curated sample output (real format)

FedRAMP Moderate · Monthly ConMon Package · 2026-05


Executive Summary

Risk trend: Stable (was improving last month — 2 new high vulnerabilities offset 3 closures)

ATO impact: No re-authorization required this cycle

Significant changes: 1 reviewed (analysis below) — does not trigger ATO refresh


1. Vulnerability Scan Triage

New Findings (since last submission)

IDAssetSeverityCVEDays OpenStatus
V-2026-0501app-prod-01CriticalCVE-2026-23414Patched 2026-05-08
V-2026-0512db-prod-02CriticalCVE-2026-18991Patch scheduled 2026-05-12
V-2026-0509web-prod-03HighCVE-2026-31227In progress — vendor fix expected 2026-05-22
V-2026-0519mon-prod-01HighCVE-2026-208914Escalating — ROD pending

CISA KEV Cross-Reference

2 of 4 critical findings overlap with CISA KEV (V-2026-0501, V-2026-0512). Both within KEV remediation due dates.

Persistent Findings (>30 days)

3 medium findings rolled forward from April:

- M-2026-0312 (CIS benchmark drift on 4 EC2) — process gap, not technical

- M-2026-0328 (TLS 1.0 enabled on legacy LB) — deprecation in progress

- M-2026-0401 (default M365 token lifetime) — exception filed, accepted by AO


2. POA&M Status Update

Total open: 23 (down 2 from April)

Milestones met this month: 7

Milestones missed: 2 (re-baselining attached as POAM-EXT-0026-05)

Items Past Milestone

IDControlOriginal DueProposed New DueJustification
POAM-0019CM-8(3)2026-05-012026-07-01Vendor inventory tool delivery delayed
POAM-0027RA-5(11)2026-04-302026-06-15Public-facing scan tool selection in progress

Closed This Month

POAM-0014, POAM-0017, POAM-0021, POAM-0025, POAM-0029, POAM-0033, POAM-0038

Closure evidence attached as separate ZIP.


3. Significant Change Analysis

Change: Migration of identity provider from Auth0 to Okta (Acme-CR-2026-0428)

Analysis against FedRAMP Significant Change Procedure §3.2:

CriterionDetermination
New authorization boundary asset classNO — Okta already in inventory as backup IdP
Change in cryptographic module FIPS validationNO — both FIPS 140-2 validated
New external system interconnectionNO — same IdP function, vendor swap
Change in data type or sensitivityNO
Significant decrease in compensating controlsNO — coverage increases

Determination: NOT a significant change per PMO Significant Change Procedures. Documented as a routine change in change register. No SAR refresh required. AO notified for awareness only.


4. Control Effectiveness Spot Check

Sampled 5 controls this month: AC-2, AC-7, AU-6, CM-3, CP-9.

- AC-2: Q2 review completed, evidence current

- AC-7: Lockout policy enforced, sample tests passed

- AU-6: Alert review SLA missed for 2 of 30 alerts (response > 5 business days). Process update issued.

- CM-3: Change approvals 100% sampled, all attested

- CP-9: Last successful backup test 2026-04-15, restore validated

Net assessment: All controls operating. One minor SLA gap (AU-6) corrected this cycle.


5. Next Month Actions

1. Close V-2026-0509 (vendor fix arrives) and V-2026-0519 (ROD by 2026-05-25)
2. Submit POAM-EXT-0026-05 re-baseline request
3. Complete TLS 1.0 deprecation (M-2026-0328)
4. Q2 access review kickoff
5. Begin pre-work for annual assessment (Q3)
Cmd+Enter to send