The Plan of Action and Milestones is the control-room for known weaknesses. Start it before the assessment so gaps are visible, owned, and moving.
POA&M Fields
| Field | Meaning | Example |
|---|
| ID | Stable tracking identifier. | POAM-0001 |
| Source | Where the weakness came from. | SAST, 3PAO, ConMon, incident, manual review |
| Control | Related NIST control or family. | RA-5, SI-2, SC-13 |
| Weakness | Plain-English description of the problem. | Container image has a high CVE. |
| Severity | High, Moderate, Low, or Operational. | High |
| Risk | Impact if not fixed. | Remote code execution risk in public API image. |
| Owner | Person or team accountable for remediation. | Platform Engineering |
| Milestones | Concrete remediation steps. | Patch base image, rebuild, rescan, redeploy. |
| Due Date | Date based on severity and policy. | [FILL IN] |
| Status | Open, In Progress, Remediated, Risk Accepted, False Positive. | Open |
| Evidence | Proof that remediation or acceptance occurred. | Scan report and release record |
| Severity | Target Window | Escalation |
|---|
| High | 30 calendar days | Security and System Owner |
| Moderate | 90 calendar days | Security and owning engineering lead |
| Low | 180 calendar days | Owning engineering lead |
| Operational | Defined by risk owner | System Owner |
Templates Register
| ID | Source | Control | Weakness | Severity | Owner | Due Date | Status | Evidence |
|---|
POAM-0001 | Readiness review | PL-2 | SSP source material exists only as template drafts. | Moderate | Security | [FILL IN] | Open | This folder |
POAM-0002 | Readiness review | RA-5 | Vulnerability scanning scope and monthly evidence package are not fully defined. | Moderate | Security | [FILL IN] | Open | 05-evidence-and-conmon-plan.mdx |
POAM-0003 | Readiness review | SR-4 | SBOM, artifact signing, and provenance are not yet required for every release. | Moderate | Platform Engineering | [FILL IN] | Open | 08-secure-sdlc-and-supply-chain-plan.mdx |
POAM-0004 | Readiness review | SC-13 | FIPS 140-3 validation status for cryptographic modules is not confirmed. | High | Platform Engineering | [FILL IN] | Open | 09-access-audit-and-data-protection-plan.mdx |
POAM-0005 | Readiness review | AU-11 | Audit log retention target and storage location are not confirmed. | Moderate | Operations | [FILL IN] | Open | 09-access-audit-and-data-protection-plan.mdx |
Risk Acceptance
Risk acceptance is not a way to hide overdue work. It must be time-bound, approved by the risk owner, tied to compensating controls, and revisited on a defined date.
| Required Item | Description |
|---|
| Risk owner | Named person with authority to accept the risk. |
| Business reason | Why remediation cannot happen within the normal window. |
| Compensating control | What reduces exposure while the gap remains open. |
| Expiration date | Date when the acceptance must be renewed or closed. |
| Evidence | Approval record and any compensating-control proof. |
Weekly Triage
- Review new findings from scans, incidents, and manual reviews.
- Deduplicate findings by root cause.
- Assign owner and severity.
- Set due date from remediation window.
- Link remediation pull request, issue, or change record.
- Escalate overdue or blocked items.
- Close only with evidence.
Closure Criteria