What is the primary purpose of a Plan of Action and Milestones (POA&M) in the NIST Risk Management Framework?
-
A
To document the organization's long-term strategic security roadmap
-
B
To track and manage the remediation of security weaknesses and deficiencies identified in an information system
-
C
To record all security incidents and their associated response actions
-
D
To schedule future security assessments and penetration tests