CGRC Plan of Action and Milestones (POA&M) — Questions and Answers
Question 1: What is the primary purpose of a Plan of Action and Milestones (POA&M) in the NIST Risk Management Framework?
- To document the organization's long-term strategic security roadmap
- To track and manage the remediation of security weaknesses and deficiencies identified in an information system (Correct answer)
- To record all security incidents and their associated response actions
- To schedule future security assessments and penetration tests
Correct answer: To track and manage the remediation of security weaknesses and deficiencies identified in an information system
A POA&M is a document that identifies tasks needing to be accomplished to correct weaknesses or deficiencies found in security controls. It includes resources required, scheduled completion dates, and responsible parties. It is not a strategic roadmap, incident log, or assessment schedule.
Question 2: Which of the following events would MOST appropriately trigger the creation of a new POA&M entry?
- A security control is assessed as 'Satisfied' during the security assessment
- A security control is assessed as 'Other Than Satisfied' during the security assessment (Correct answer)
- The system receives a full Authorization to Operate (ATO)
- A new security policy is approved by senior leadership
Correct answer: A security control is assessed as 'Other Than Satisfied' during the security assessment
POA&M entries are created when security controls are found to be 'Other Than Satisfied' (i.e., weaknesses or deficiencies are identified). Controls assessed as Satisfied do not need remediation tracking. An ATO and new policies do not automatically generate POA&M entries.
Question 3: Who is primarily responsible for reviewing and accepting the risk associated with items listed on a POA&M?
- The Information System Security Officer (ISSO)
- The Security Control Assessor (SCA)
- The Authorizing Official (AO) (Correct answer)
- The System Owner
Correct answer: The Authorizing Official (AO)
The Authorizing Official is responsible for accepting the risk of operating a system with known weaknesses documented in the POA&M. The ISSO and System Owner manage the POA&M day-to-day, and the SCA identifies findings — but formal risk acceptance belongs to the AO.
Question 4: During continuous monitoring, an organization discovers that a POA&M item scheduled for completion 60 days ago has not been remediated and no extension was approved. What is the BEST course of action?
- Automatically revoke the system's Authorization to Operate
- Delete the POA&M item and conduct a new assessment to establish a fresh baseline
- Escalate the overdue item to the Authorizing Official and document the updated status and revised milestones (Correct answer)
- Transfer the item to the System Security Plan as an accepted risk
Correct answer: Escalate the overdue item to the Authorizing Official and document the updated status and revised milestones
Overdue POA&M items must be escalated to the Authorizing Official, who has the authority to accept the continued risk, demand immediate remediation, or revoke authorization. Revoking the ATO is an option the AO may choose, but it is not automatic. Deleting items or transferring them to the SSP as accepted risk without AO involvement is inappropriate.
Question 5: Which of the following is a required data element in a properly formatted POA&M entry?
- The full name and clearance level of the user who discovered the weakness
- The estimated cost and scheduled completion date for remediation (Correct answer)
- The names of all vendors who provided the affected system components
- A cryptographic hash of the system configuration at the time the weakness was found
Correct answer: The estimated cost and scheduled completion date for remediation
Required POA&M fields include the weakness description, resources required (including estimated cost), responsible parties, and scheduled completion milestones/dates. Discoverer identity, vendor lists, and configuration hashes are not standard required POA&M elements per OMB and NIST guidance.
Question 6: According to OMB guidance, how frequently must federal agencies report on the status of their POA&Ms?
- Daily, as part of real-time security dashboards
- Quarterly, as part of FISMA reporting requirements (Correct answer)
- Annually, coinciding with the authorization renewal
- Only when a new weakness is discovered and added to the POA&M
Correct answer: Quarterly, as part of FISMA reporting requirements
OMB guidance under FISMA requires agencies to report POA&M status quarterly. This ensures that weaknesses are being tracked and remediated on an ongoing basis rather than only at annual review points or ad hoc discovery events.
What is the primary purpose of a Plan of Action and Milestones (POA&M) in the NIST Risk Management Framework?