DI-MGMT-82190
Information Security (IS) Plan of Action & Milestones (POA&M)
The IS Posture POA&M provides information on the current state of the network security infrastructure and information needed to understand and improve the security posture.
Approval DateMarch 22, 2018
AMSC NumberN9907
Preparing ActivitySH
Project NumberMGMT-2018-020
OPR—
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The IS Posture POA&M provides information on the current state of the network security infrastructure. It provides information needed to understand and improve the security posture.
This data item description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirement as delineated in the contract.
DoDI 8510.1 Risk Management Framework (RMF) for DoD Information Technology (IT) is available at: http://www.esd.whs.mil/Directives/issuances/dodi/
Preparation Instructions
1Format.The IS Posture POA&M shall follow the enterprise Mission Assurance Support System (eMASS) System Level Microsoft Excel format.
2Content.The IS Posture POA&M shall include a network POA&M that contains the following:
2.1.3Component Name/ Information System Owner
2.1.4Department of Defense (DoD) Information Technology (IT) registration number
2.1.6System Identification
2.1.7IS Type/System Record Type
2.1.10Office of Management and Budget (OMB) Project Identification
2.2Weakness.Weaknesses shall be specified consecutively and numerically. This section shall include the following:
2.2.1Specific Security Weakness Identified via DoD tools or Information Assurance Control (IAC) Tests.
2.2.2Security Actions and Administrative Actionse.g., finish Systems Requirements Review (SRR) tests, and register system in Department of Defense Information Technology Portfolio Registration-Department of the Navy (DITPR-DON))
2.2.3If not applicable, then Not Applicable (NA) shall be included
2.3The severity Category (CAT).The severity CAT is the residual risk and shall be specified as CAT I, II, III. If not applicable, this shall be the original Defense Information Systems Agency (DISA) Severity and identified as "raw".
2.4Information Assurance Control (IAC) and Impact Code.This section shall include the following:
2.4.1Information Assurance (IA) control assigned to the finding
2.4.2Impact code assigned to the IA control.Note that the impact code shall not change.
2.5POC.Identify Office/Organization responsible for resolving the security weakness.
2.6.4Include NA for CAT III weaknesses
2.7Estimated Completion Date.This shall include:
2.7.1Date when the weakness is scheduled to be resolved.Status column shall identify completion date updates (e.g., Not Okay = TBD, FY10, 3Q, etc)
2.7.2If risks are accepted by Office of the Designating Authority (ODAA), then NA shall be specified.
2.8Milestones with Completion Date
2.8.1Identify specific requirements to correct weaknesses
2.8.2Column 8 (Milestone change) shall identify changes to any milestones
2.8.3If risks are accepted by ODAA, then NA shall be specified.
2.9.1Updates to the milestones/Completion date shall be included
2.9.2If risks are accepted by ODAA, then NA shall be specified.
2.10Source Identifying Weakness
2.10.1This shall identify the source of the weakness(i.e., Security Test Implementation Guide (STIG), Security Checklists, Retina, gold disk, etc.)
2.10.2This shall identify the weakness type.
2.10.3Include weakness identification(i.e., STIG ID, Vulnerability Management System Identification (VMS ID), Audit ID, etc.).
2.11.1Shall specify status as "ongoing", "completed, or "risk accepted", "not valid - pending", "TBD", etc.
2.11.2Adequate explanation in the comments column shall be included.Completion date shall be included if status is "completed".
2.11.3"Risk accepted" status shall be identified only after the risk is accepted by the ODAA.
2.11.4Date of acceptance shall be specified.
2.12.1Necessary information, justification and mitigation shall be included.
2.12.2This shall also contain justification for NA IA controls.
Schema v3.0Community-maintained · Verify against ASSIST