Plan of Action and Milestones
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of CA-5 — Plan of Action and Milestones. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of CA-5 — Plan of Action and Milestones. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Plans of action and milestones are useful for any type of organization to track planned remedial actions. Plans of action and milestones are required in authorization packages and subject to federal reporting requirements established by OMB.
Enhancements NIST SOURCE
CA-5(1) Automation Support for Accuracy and Currency LOW MODERATE HIGH
Ensure the accuracy, currency, and availability of the plan of action and milestones for the system using [automated mechanisms].
Discussion
Using automated tools helps maintain the accuracy, currency, and availability of the plan of action and milestones and facilitates the coordination and sharing of security and privacy information throughout the organization. Such coordination and information sharing help to identify systemic weaknesses or deficiencies in organizational systems and ensure that appropriate resources are directed at the most critical system vulnerabilities in a timely manner.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CA-5 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency at which to update an existing plan of action and milestones based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities is defined;
- a plan of action and milestones for the system is developed to document the planned remediation actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system;
- existing plan of action and milestones are updated <CA-05_ODP frequency> based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.
Examine
[SELECT FROM: Assessment, authorization, and monitoring policy; procedures addressing plan of action and milestones; control assessment plan; control assessment report; control assessment evidence; plan of action and milestones; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with plan of action and milestones development and implementation responsibilities; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Mechanisms for developing, implementing, and maintaining plan of action and milestones].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CA-5. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Assessment, authorization, and monitoring policy
- procedures addressing plan of action and milestones
- control assessment plan
- plan of action and milestones
- system security plan
- privacy plan
Testing
- Mechanisms for developing, implementing, and maintaining plan of action and milestones
Other Records
- control assessment report
- control assessment evidence
- other relevant documents or records