A federal cloud system goes to authorization with open assessment findings — what must its plan of action and milestones contain under NIST SP 800-37 and CA-5?
answer
- tasks, resources, milestones, dates
- before or after authorization
- risk acceptance needs no entry
- updated from assessments and monitoring
- prioritize by risk
basics
~20 sUnder NIST SP 800-37 task A-6, the plan of action and milestones lists each deficiency's remediation tasks, resources, milestones and scheduled completion dates. The authorizing official reviews it, and control CA-5 requires it to be updated from assessments, audits and continuous monitoring.
solid answer
~50 sIn the RMF, the assessor's findings go first to **initial remediation** and reassessment (task A-5); what remains goes into the **plan of action and milestones** (task A-6). SP 800-37 says a POA&M includes the **tasks** to be accomplished, with a recommendation for completion **before or after authorization**, the **resources** required, the **milestones**, and the **scheduled completion dates**. It is part of the **authorization package** and is reviewed by the **authorizing official**, who must agree with the planned remediation. An entry is **not necessary** when the AO accepts a deficiency as **residual risk**, though the deficiency stays in the assessment report. Items are **prioritized** by a risk assessment, the system's categorization and the criticality of each deficiency. Under SP 800-53 **CA-5**, the POA&M is updated at an organization-defined frequency from control assessments, independent audits and continuous monitoring.
go deeper
Recall that a POA&M lists remediation for findings with tasks, resources, milestones and completion dates.
Explain the path from assessment findings through initial remediation to the POA&M, and the AO's role in reviewing it.
Show how you would prioritize and run a POA&M after authorization: risk-based ordering, verified closure, and updates from continuous monitoring.
Weigh when to ask the AO to accept residual risk versus committing remediation resources, and how that shapes the authorization decision.
## Where findings go A federal cloud service reaching authorization almost never has zero findings. What matters is how they are handled. NIST SP 800-37 Rev. 2, the Risk Management Framework, sets the path in its **Assess** step: 1. **Task A-4** - the assessor documents findings and recommendations in the security and privacy assessment reports. 2. **Task A-5** - the organization conducts **initial remediation** on the controls and the assessor **reassesses** remediated controls. 3. **Task A-6** - the system owner prepares the **plan of action and milestones (POA&M)** from the findings and recommendations that remain. SP 800-53 Rev. 5 control **`CA-5` Plan of Action and Milestones** requires the same artefact for the system: document planned remediation actions to correct weaknesses or deficiencies found during assessment and to reduce or eliminate known vulnerabilities, and **update** it at an organization-defined frequency based on findings from **control assessments, independent audits or reviews, and continuous monitoring**. The control's discussion notes that POA&Ms are required in authorization packages and subject to federal reporting requirements. ## What a POA&M entry contains Per SP 800-37 task A-6, a POA&M includes: - **Tasks** to be accomplished, with a recommendation for completion **before or after system authorization**; - **Resources** required to accomplish the tasks; - **Milestones** established to meet the tasks; - **Scheduled completion dates** for the milestones and tasks. In practice each entry also references the finding and control it addresses, the owner, and its current status, so the plan can be tracked and reported. | Field | Purpose | |---|---| | Finding and affected control | Traceability back to the assessment report | | Remediation tasks | What will actually be done | | Resources | People, hardware, software or tools needed | | Milestones and dates | Checkpoints the AO can track | | Before or after authorization | Whether the AO should expect it closed before the decision | ## Who agrees, and when no entry is needed The **authorizing official (AO)** reviews the POA&M to ensure agreement with the planned remediation, then uses it to monitor progress. SP 800-37 adds an important nuance: deficiencies are either **accepted by the AO as residual risk** or **remediated**. A POA&M entry is **not necessary** when the AO accepts a deficiency as residual risk, but the deficiency is still documented in the assessment report. ## Prioritization SP 800-37 expects a consistent, organization-wide process that uses a **prioritized approach to risk mitigation**. Prioritization is informed by: - the system's **security categorization**; - security, privacy and supply chain **risk assessments**; - the **specific deficiencies** and their **criticality** - their direct or indirect effect on the system's posture and the organization's mission; - the proposed **risk mitigation approach** and available resources. ## Running it after authorization - **Keep it current**: CA-5 requires updates at a defined frequency, and CA-5(1) adds automated mechanisms to keep it accurate and available. - **Feed it from monitoring**: new findings from continuous monitoring enter the same plan. - **Close with evidence**: an item closes when remediation is verified, not when a ticket is marked done. - **Watch slippage**: missed milestones are a signal to the AO that residual risk is higher than planned. ## Common mistakes - Writing POA&M items as vague intentions ("improve logging") with no tasks or dates the AO can track. - Letting milestones slip silently instead of re-planning them with the AO's agreement. - Treating risk acceptance as a way to avoid work, when it is a formal decision by the AO recorded against the assessment report. - Keeping a separate list for findings from continuous monitoring, so the AO never sees the whole picture. Other programmes time-box POA&Ms more strictly. The CMMC rule, for instance, allows a POA&M only for certain requirements and requires closeout within 180 days, or the conditional status expires. A strong answer lists the A-6 contents, explains the AO's review and the residual-risk alternative, and shows how CA-5 keeps the plan live after authorization.
- When is a finding left out of the POA&M?When the authorizing official accepts the deficiency as residual risk. SP 800-37 says a POA&M entry is then unnecessary, but the deficiency remains documented in the assessment report.
- What updates a POA&M after authorization?Under CA-5, updates follow findings from control assessments, independent audits or reviews, and continuous monitoring, at a frequency the organization defines. New findings are added and closed items are verified.
saying these in an interview costs you the question
- Treats the POA&M as a list of findings with no tasks or dates
- Believes every accepted risk still needs a POA&M entry
- Closes items when a ticket is marked done, without verification
- Updates the POA&M only at reauthorization
- Prioritizes items by ease of fixing rather than risk