A POA&M (plan of action and milestones) is a document that lists each security requirement an organization has not fully met, the specific weakness, the planned fix, the owner, the milestones and the target completion date.
In NIST SP 800-171 Rev 3, the POA&M is requirement 03.12.02 Plan of Action and Milestones, and it works alongside the system security plan (SSP).
Example entry: “03.03.01 Event Logging. Weakness: logs from 2 of 3 file servers are not forwarded for review. Planned action: install the forwarding agent and add both servers to the weekly review procedure. Owner: Systems Administrator. Target completion: 30 days.”
A POA&M is used to track and manage deficiencies or weaknesses found in cybersecurity controls. A POAM can be formatted in a simple spreadsheet, so no special tools are needed to generate and maintain a POAM.
While there is no current “gold standard” for what a POAM is meant to contain. FedRAMP’s POAM template is the most common basis leveraged as a starting point. In general, a POAM includes the following criteria:
Organizations use POAMs to ensure accountability and visibility into their ongoing cybersecurity improvement efforts. In requirements like FedRAMP, RMF and CMMC, maintaining POAMs is a mandatory requirement for demonstrating ongoing risk management and compliance.