Number | Title | Impact | Priority | Subject Area |
---|---|---|---|---|
CA-5 | Plan Of Action And Milestones | LOW | P3 | Security Assessment And Authorization |
Instructions |
---|
The organization: CA-5a. Develops a plan of action and milestones for the information system to document the organization�s planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system; and CA-5b. Updates existing plan of action and milestones Assignment: organization-defined frequency based on the findings from security controls assessments, security impact analyses, and continuous monitoring activities. |
Guidance |
---|
Plans of action and milestones are key documents in security authorization packages and are subject to federal reporting requirements established by OMB. |
Enhancements | ||
---|---|---|
The organization employs automated mechanisms to help ensure that the plan of action and milestones for the information system is accurate, up to date, and readily available. |