Organizational Control: Plan Of Action And Milestones

Control ID: CA-5 Plan Of Action And Milestones Family: Security Assessment and Authorization Source: NIST 800-53r4
Control: The organization:
  1. Develops a plan of action and milestones for the information system to document the organization’s planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system; and
  2. Updates existing plan of action and milestones [Assignment: organization-defined frequency] based on the findings from security controls assessments, security impact analyses, and continuous monitoring activities.
Supplemental Guidance:
Plans of action and milestones are key documents in security authorization packages and are subject to federal reporting requirements established by OMB.

Related Controls: CA-2, CA-7, CM-4, PM-4
Control Enhancements: N/A
References: OMB Memorandum 02-01; NIST Special Publication 800-37.
Mechanisms:
Protocol Implementation Conformance Statements: N/A