7.5 Ongoing Remediation, POA&M Sustainment & Annual Reviews

Key Takeaways

  • The Plan of Action and Milestones (POA&M - CA-5) is a dynamic, living governance artifact used to track, prioritize, and remediate identified vulnerabilities throughout the operational lifecycle.
  • Effective POA&M sustainment requires regular update rhythms (daily/weekly/monthly), strict adherence to remediation SLAs based on vulnerability severity, and formal escalation of aging items.
  • Ongoing audit activities combine rotational control testing (e.g., evaluating one-third of controls annually so 100% are verified over a multi-year cycle) with required vulnerability scanning, personnel interviews, and documentation review, because scans and documents alone cannot reveal the gap between a written process and actual practice.
  • FISMA mandates annual compliance reviews by agency Chief Information Officers (CIOs) and Senior Agency Officials for Privacy (SAOPs) reported directly to OMB and Congress via CyberScope.
  • Agency Inspectors General (IGs) conduct annual independent evaluations using Council of the Inspectors General on Integrity and Efficiency (CIGIE) maturity metric baselines.
Last updated: August 2026

7.5 Ongoing Remediation, POA&M Sustainment & Annual Reviews

Security authorization is not an end state; it is an operational baseline. Once a system enters the operational phase of the Risk Management Framework (RMF), the system's security posture is continually challenged by newly discovered software vulnerabilities, changing threat vectors, configuration drift, and audit findings.

To ensure that identified security deficiencies are systematically tracked and remediated rather than forgotten, organizations maintain an active Plan of Action and Milestones (POA&M) per NIST SP 800-53 control CA-5. Furthermore, statutory mandates—specifically the Federal Information Security Modernization Act (FISMA)—require structured annual reviews and independent Inspector General (IG) audits to ensure enterprise-wide compliance.


Sustaining the Plan of Action and Milestones (POA&M per CA-5)

The Plan of Action and Milestones (POA&M) is the primary operational management tool used by the Authorizing Official (AO), Information System Security Manager (ISSM), and Information System Owner (ISO) to track corrective actions for known weaknesses.

┌─────────────────────────────────────────────────────────────────────────────┐
│                     CONTINUOUS POA&M SUSTAINMENT CYCLE                      │
│                                                                             │
│  Deficiency Sources:                                                        │
│  • Continuous Vulnerability Scans (Nessus/Qualys)                           │
│  • Security Control Assessments (SCAs)                                      │
│  • Incident Response Post-Mortems                                           │
│  • IG Audits & Penetration Tests                                            │
│      │                                                                      │
│      ▼                                                                      │
│  1. Ingestion & Triage: Assign Severity, Root Cause & Resource Needs        │
│      │                                                                      │
│      ▼                                                                      │
│  2. Actionable Milestone Definition: Establish Measurable Steps & POC       │
│      │                                                                      │
│      ▼                                                                      │
│  3. Remediation Execution within Defined Severity SLAs                      │
│      │ • Critical: ≤ 15-30 Days                                             │
│      │ • High: ≤ 30 Days | Moderate: ≤ 90 Days | Low: ≤ 180 Days            │
│      │                                                                      │
│      ▼                                                                      │
│  4. Independent Verification & Evidence Validation (Scan / Test)            │
│      │                                                                      │
│      ▼                                                                      │
│  5. Formal Closure in Enterprise GRC Repository (eMASS / CSAM)              │
└─────────────────────────────────────────────────────────────────────────────┘

Essential Data Elements of a Compliant POA&M

Under Office of Management and Budget (OMB) memoranda and NIST guidelines, every POA&M entry must contain specific, standardized data fields:

  1. Weakness Identifier: Unique tracking ID (e.g., POAM-2026-SYS1-042).
  2. Weakness Description: Detailed technical summary of the deficiency, affected Common Weakness Enumeration (CWE), or non-compliant NIST SP 800-53 control.
  3. Source of Weakness: Origin of discovery (e.g., Annual SCA, Automated Vulnerability Scan, IG Audit, Penetration Test, Threat Intel Alert).
  4. Risk / Severity Rating: High, Moderate, or Low impact rating based on potential business/mission harm.
  5. Point of Contact (POC): Named individual accountable for driving remediation (cannot be a generic team).
  6. Resource Requirements: Estimated financial funding, staffing hours, software licenses, or hardware acquisitions required to fix the issue.
  7. Scheduled Completion Date: Target remediation deadline aligned with organizational SLAs.
  8. Milestones with Interim Completion Dates: Discrete, sequential operational sub-tasks demonstrating measurable progress toward final remediation.
  9. Status & Mitigation Notes: Current state (Open, In Progress, Under Review, Completed, Delayed) and compensating controls active during remediation.

Remediation Service Level Agreements (SLAs) and Aging Vulnerabilities

Federal guidelines and industry best practices establish strict timelines for remediating vulnerabilities based on CVSS / FIPS impact scores:

Vulnerability SeverityStandard Federal Remediation SLAEscalation Pathway for Overdue Items
Critical (CVSS 9.0 - 10.0)15 to 30 Days (or emergency 72-hour patch for active zero-days under CISA Binding Operational Directives).Immediate daily briefing to CISO; escalation to AO for risk acceptance or system disconnection warning.
High (CVSS 7.0 - 8.9)30 DaysWeekly tracking by ISSM; mandatory formal justification memo to AO if deadline is missed.
Moderate (CVSS 4.0 - 6.9)90 DaysMonthly review in executive risk dashboards; prioritized in quarterly release cycles.
Low (CVSS 0.1 - 3.9)180 to 365 Days (or accepted risk)Tracked in routine maintenance backlog; bundled into annual major upgrades.

[!WARNING] Aging POA&M Risk: Stale POA&M items that remain open past their scheduled completion date represent severe governance failures. An accumulation of overdue High/Critical POA&Ms is the primary trigger for Inspector General audit findings, OMB compliance penalties, and Authorizing Official revocation of an ATO (issuing a Denial of Authorization to Operate - DATO).


Ongoing Security Assessments and Rotational Control Testing

Under legacy compliance, organizations attempted to assess 100% of security controls during a massive triennial audit. In modern continuous monitoring, organizations execute Rotational Control Assessments to distribute assessment effort evenly across time.

┌─────────────────────────────────────────────────────────────────────────────┐
│                     ROTATIONAL ASSESSMENT 3-YEAR MODEL                      │
│                                                                             │
│  ┌────────────────────────┐ ┌────────────────────────┐ ┌──────────────────┐  │
│  │         YEAR 1         │ │         YEAR 2         │ │      YEAR 3      │  │
│  │ • 100% High-Volatility │ │ • 100% High-Volatility │ │• 100% High-Volat.│  │
│  │   Controls (AC, SI, CM)│ │   Controls (AC, SI, CM)│ │  Controls (AC..) │  │
│  │ • 33% Moderate Controls│ │ • 33% Moderate Controls│ │• 34% Mod. Controls│ │
│  │ • Core Governance (PL) │ │ • Contingency (CP/IR)  │ │• Physical (PE/PS)│  │
│  └───────────┬────────────┘ └───────────┬────────────┘ └────────┬─────────┘  │
│              │                          │                       │            │
│              └──────────────────────────┼───────────────────────┘            │
│                                         ▼                                    │
│  ┌────────────────────────────────────────────────────────────────────────┐  │
│  │    100% of All Baseline Controls Fully Assessed Over 3-Year Cycle      │  │
│  │    + Real-Time Continuous Telemetry Across Entire System Lifecycle     │  │
│  └────────────────────────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────────────────────┘

Rotational Testing Architecture

  • Continuous / High-Frequency Controls: High-volatility technical controls (e.g., AC-2, CM-6, SI-2, SI-4) are assessed continuously or monthly via automated tools.
  • Partitioned Moderate- and Low-Volatility Controls: The remaining operational, administrative, and physical controls are divided into three equal tranches:
    • Year 1: Tranche A (e.g., Access Control policies, Identification & Authentication, System & Services Acquisition).
    • Year 2: Tranche B (e.g., Contingency Planning, Incident Response, Maintenance, Media Protection).
    • Year 3: Tranche C (e.g., Physical and Environmental Protection, Personnel Security, Awareness Training, System Integrity).
  • Result: 100% of all NIST SP 800-53 controls are rigorously evaluated over a 36-month period without overwhelming engineering resources.

Event-Triggered Assessments

In addition to rotational schedules, targeted assessments are triggered immediately upon:

  1. Discovery of an active, widespread security breach or significant control failure.
  2. Implementation of a major architectural modification (e.g., migrating from on-premises hosting to a public cloud environment).
  3. Re-categorization of system impact level (e.g., Moderate to High due to new mission requirements).

Annual FISMA Reviews and Inspector General (IG) Audits

The Federal Information Security Modernization Act (FISMA) establishes statutory requirements for federal agencies and commercial contractors operating federal systems.

┌─────────────────────────────────────────────────────────────────────────────┐
│                     STATUTORY ANNUAL FISMA REPORTING                        │
│                                                                             │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ Agency Head / CIO / CISO / SAOP Annual Self-Assessment                │  │
│  │ • Evaluates all agency systems, ATO currency, and POA&M health        │  │
│  │ • Submits annual report via CyberScope to OMB and Congress            │  │
│  └───────────────────────────────────┬───────────────────────────────────┘  │
│                                      │ Concurrent Independent Oversight     │
│                                      ▼                                      │
│  ┌───────────────────────────────────────────────────────────────────────┐  │
│  │ Agency Inspector General (IG) Independent Evaluation                  │  │
│  │ • Independent audit using CIGIE Cybersecurity Maturity Metrics        │  │
│  │ • Rates agency maturity across NIST CSF functions (Levels 1 to 5)     │  │
│  │ • Reports unvarnished findings directly to OMB and Congress           │  │
│  └───────────────────────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────────────────────┘

1. Agency CIO and SAOP Annual Reviews

  • Statutory Mandate: FISMA requires the Chief Information Officer (CIO) and Senior Agency Official for Privacy (SAOP) to conduct an annual review of the information security and privacy program.
  • Scope: Verifies that 100% of operational systems have an active, valid ATO, that POA&Ms are maintained, that incident response capabilities meet federal SLAs, and that privacy impact assessments (PIAs) are current.
  • Reporting Destination: Automated metrics and formal annual reports are submitted to the Office of Management and Budget (OMB), Department of Homeland Security (DHS / CISA), and Congressional Committees via the CyberScope portal.

2. Inspector General (IG) Independent Evaluations

  • Statutory Mandate: FISMA mandates an annual independent evaluation conducted by the agency's Office of the Inspector General (OIG) or an independent external auditor.
  • Methodology (CIGIE Metrics): Evaluated against the Council of the Inspectors General on Integrity and Efficiency (CIGIE) maturity model, structured around the NIST Cybersecurity Framework (CSF) functions (Identify, Protect, Detect, Respond, Recover).

CIGIE Five-Level Maturity Model

Maturity LevelLevel NameKey Operational Characteristics
Level 1Ad HocPolicies, procedures, and strategy are not formalized; activities are reactive and inconsistent.
Level 2DefinedPolicies and procedures are documented and approved, but operational implementation is inconsistent across business units.
Level 3Consistently ImplementedSecurity policies, procedures, and controls are documented and consistently implemented across all enterprise systems.
Level 4Managed and MeasurableQuantitative metrics and KPIs/KRIs are collected, analyzed, and used to actively manage risk and evaluate control performance.
Level 5OptimizedContinuous institutional improvement through advanced automation, artificial intelligence, predictive threat modeling, and adaptive defense.

[!NOTE] FISMA Compliance Benchmark: To achieve an "Effective" cybersecurity program rating from the Inspector General, federal agencies are generally required to achieve a minimum maturity score of Level 4 (Managed and Measurable) across core domains.


Real-World RMF Scenario: The Critical POA&M Breach

Scenario: During an annual FISMA audit of a federal benefits administration database, the Inspector General discovers an open POA&M item for unencrypted database backups at rest (SC-28). The POA&M was opened 18 months earlier with an initial 90-day target resolution date. The milestone dates had been rolled over four consecutive times by the ISSO without executive justification or compensating controls.

GRC Impact: The Inspector General cites the agency for a "Material Weakness" in governance. The Authorizing Official (AO) issues a formal Show-Cause letter to the System Owner. To prevent immediate ATO revocation, the agency reallocates emergency capital funding to deploy automated transparent database encryption within 21 days, establishes an executive POA&M Review Board that meets bi-weekly, and introduces strict rules prohibiting milestone rollovers without written CISO approval.


Common Exam Traps

  • ⚠️ Trap: Assuming a POA&M is only created during the initial RMF Step 4 assessment. A POA&M is a living document maintained throughout the entire operational lifecycle, ingesting new vulnerabilities from continuous scans, incident reports, and ongoing audits.
  • ⚠️ Trap: Believing rotational assessments eliminate the need to test high-volatility controls annually. High-volatility technical controls (e.g., access control, patching, auditing) must be tested continuously or annually, while lower-volatility controls can be rotated across the 3-year cycle.
  • ⚠️ Trap: Confusing the role of the CIO with the Inspector General (IG) under FISMA. The CIO conducts an internal agency self-assessment, whereas the IG conducts an independent external evaluation reporting directly to OMB and Congress.

Ongoing Audit Activities: Testing, Interviews and Documentation Review

CGRC task 7.3 requires the organization to engage in audit activities based on compliance requirements throughout operations, and it names three activities explicitly. All three are recurring obligations, not authorization-phase events.

ActivityWhat It Covers OperationallyWhy It Cannot Be Skipped
Required testing and vulnerability scanningAuthenticated scans on the defined cadence, configuration benchmark checks, penetration testing where the framework or contract requires it, and control-specific functional testsTechnical drift is invisible without measurement; scan results are the highest-volume continuous monitoring evidence
Personnel interviewsStructured discussions with administrators, operators, incident responders, and control owners about how a process is actually performedDocuments describe intent; interviews reveal practice. A procedure can be perfectly written and universally ignored
Documentation review and updatePolicies, procedures, plans, SSP content, SLAs, and third-party agreements checked against current requirements and current realityDocumentation that no longer describes the system is a finding and misleads staff who follow it

Why Interviews Are Irreplaceable

Automated scanning and document review together still leave a blind spot that only interviews close: the gap between the documented process and the operating practice. A configuration scan proves a setting is correct today. A procedure document proves someone wrote down how the review should work. Neither reveals that the quarterly access review is performed by one administrator who approves the whole list without examining it, or that the on-call engineer has never read the escalation procedure they are named in.

Effective ongoing interviews follow a few disciplines:

  • Interview the person who performs the work, not only their manager. Managers describe the designed process; practitioners describe the executed one.
  • Ask for a walkthrough rather than a yes/no confirmation. "Show me how you handled the last one" surfaces far more than "do you follow the procedure?"
  • Corroborate against artifacts. An interview claim that reviews occur monthly should be checkable against dated review records — this is method triangulation applied continuously rather than only at formal assessment.
  • Record the interview with participants, date, topics, and outcomes, since an undocumented interview produces no evidence.

Interview findings frequently identify training gaps and procedural defects that scanning can never detect, and those findings feed the same loop as any other: POA&M entries where remediation is required, documentation updates where the written process is wrong, and training assignments where the process is right but unknown.

[!NOTE] Interviews are also how you detect a control that is being bypassed. When a control obstructs the mission, staff work around it, and the workaround is rarely documented. Scanning shows the control enabled; the interview reveals the shadow process that routes around it. A control that exists but is systematically circumvented provides no protection while producing false assurance — which is exactly the condition ongoing audit activities exist to surface.

Loading diagram...
Continuous POA&M Sustainment, Rotational Testing, and FISMA Reporting Architecture
Test Your Knowledge

An enterprise manages a FIPS 199 Moderate impact system containing 250 security controls. Rather than conducting an exhaustive full-system audit every 3 years, what rotational assessment strategy complies with modern RMF continuous monitoring guidelines?

A
B
C
D
Test Your Knowledge

Under NIST SP 800-53 control CA-5 and OMB reporting guidelines, which of the following elements is MANDATORY for every entry in a Plan of Action and Milestones (POA&M)?

A
B
C
D
Test Your Knowledge

What is the primary statutory difference between the annual FISMA review conducted by an agency's Chief Information Officer (CIO) and the annual evaluation conducted by the agency's Inspector General (IG)?

A
B
C
D
Test Your Knowledge

A continuous monitoring programme relies exclusively on automated configuration scanning and annual document review. Which compliance weakness does the absence of personnel interviews most directly create?

A
B
C
D