IAO-05.1 ยท Plan of Action & Milestones (POA&M) Automation

Control Description

Automated mechanisms exist to help ensure the Plan of Action and Milestones (POA&M), or similar risk register, is accurate, up-to-date and readily-available.

Control Question
Assessment question for control validation

Does the organization use automated mechanisms to help ensure the Plan of Action and Milestones (POA&M), or similar risk register, is accurate, up-to-date and readily-available?

Control Weighting
2
Validation Cadence
Quarterly
NIST CSF Function
Detect
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 3 - Tactical