Attachment 0030 - POAMImportTemplate RM Standard.xlsm.xlsx

XLSX spreadsheet 74 KB Posted

Attached to
RFP for Integrated Battle Command System (IBCS) LRIP/FRP Federal contract opportunity
Solicitation number
W31P4Q-20-R-0015
Issued by
Department of the Army Materiel Command Contracting Command Redstone Arsenal

About this file

This document contains a Plan of Action and Milestones (POA&M) template for documenting vulnerabilities and corrective actions related to Risk Management Framework systems. The template includes fields for capturing the POA&M item ID, security control information, office and point of contact details, resources required, scheduled completion dates, milestones, status updates, severity ratings, and recommended actions. Instructions are provided on how to populate the fields to import POA&M items into an automated system. The template does not specify any required products or services but rather provides a standardized means of documenting vulnerability remediation plans according to Risk Management Framework requirements.

View the file

Other files for this federal contract opportunity

Other files attached to RFP for Integrated Battle Command System (IBCS) LRIP/FRP, newest first.
File Type Posted
EXHIBIT A - CONTRACT DATA ITEM REQUIREMENTS LIST (CDRL) - 24NOV2020.pdf PDF
Exhibit C- IBCS DSL - 24NOV2020.docx DOCX document
Attachment 0002 - AIAMD System of Systems (SoS)(MIS-PRF-56500).pdf PDF
Attachment 0004b - Relay Acceptance Test Procedures_FINAL.docx DOCX document
Attachment 0004d - Operator Procedures For IFMC GSIL.docx DOCX document
Attachment 0005 - Software Installation Instructions.docx DOCX document
Attachment 0008 - AIAMD IUID Plan Appendix A - IUID Candidates List Data Items.pdf PDF
Attachment 0009 - R and M Prediction Report.docx DOCX document
Attachment 0010a.3 – R003 KG-250X-FMECA.xlsx XLSX spreadsheet
Attachment 0010a.7 – R007 Relay Network Switch-Parvus Switch-FMECA.xlsx XLSX spreadsheet
Attachment 0010a.9 – R015 PDU Assembly-FMECA.xlsx XLSX spreadsheet
Attachment 0010a.13 – R031 Black Router--FMECA.xlsx XLSX spreadsheet
Attachment 0010c.3 – E048 HRFU-FMECA.xlsx XLSX spreadsheet
Attachment 0010c.8 – E053 Shelter Time Server-FMECA.xlsx XLSX spreadsheet
Attachment 0010c.9 – E059 Shelter Switch – 01-FMECA.xlsx XLSX spreadsheet
Attachment 0010d.7 – E153 RS112 Server -06 Shelter with PT-FMECA.xlsx XLSX spreadsheet
Attachment 0010d.8 – E153 RS112 Server -07 Shelter with PT-FMECA.xlsx XLSX spreadsheet
Attachment 0010e.9 – E147 – Table 3 Assembly-FMECA.xlsx XLSX spreadsheet
Attachment 0012 - Risk Management Plan.pdf PDF
Attachment 0013c - IBCS-A301-003 Vol II Instructor Guide_redacted.pdf PDF
Attachment 0013f - D-IBCS-0428-001_Delta_Software_SG_redacted.pdf PDF
Attachment 0013g - D-IBCS-0471_Delta2_Suppl_PE_redacted.pdf PDF
Attachment 0014 RevC - Technical Library.docx DOCX document
Attachment 0016 - Example Cage Code and Cognizant DCMA DCAA Information.xlsx XLSX spreadsheet
Attachment 0022a - CASS to PDRS.docx DOCX document
Attachment 0022a.1.e - ALH-215333 00 S-280 CASS INSTALLA.pdf PDF
Attachment 0022a.1.h - PL-ALH-211130 00 CABLE ASSEMBLY C.pdf PDF
Attachment 0022a.4 - CASS Task Purpose.v2.pptx PPTX presentation
Attachment 0025 - DD254.pdf PDF
Attachment 0010b.6 – E030 KVM Console-FMECA.xlsx XLSX spreadsheet
Attachment 0010a.5 – R005 SCIM-FMECA.xlsx XLSX spreadsheet
Attachment 0013i - D-IBCS-0473_Adv_NetMgr.pdf PDF
Attachment 0023 - IBCS LRIP FRP DO 0001 Pricing Template_22Oct2020.xlsx XLSX spreadsheet
Attachment 0003 - GFP LRIP FRP - 3SEP2020.xlsx XLSX spreadsheet
Attachment 0007 - AIAMD Requirements Prioritization 1-n table.docx DOCX document
Attachment 0010 - FMECA.docx DOCX document
Attachment 0010a.16 – R034 Media Converter Power Supply-FMECA.xlsx XLSX spreadsheet
Attachment 0010b.3 – E005 Blower Assembly-FMECA.xlsx XLSX spreadsheet
Attachment 0010b.8 – E032 R112 Shelter – Server Stack – 02-FMECA.xlsx XLSX spreadsheet
Attachment 0010b.9 – E033 R112 Shelter – Server Stack – 03-FMECA.xlsx XLSX spreadsheet
Attachment 0010c.1 – E043 Firewall Red-FMECA.xlsx XLSX spreadsheet
Attachment 0010c.4 – E049 BPU-FMECA.xlsx XLSX spreadsheet
Attachment 0010c.7 – E052 SCIM-FMECA.xlsx XLSX spreadsheet
Attachment 0010c.14 – E064 Shelter Router Black – FMECA.xlsx XLSX spreadsheet
Attachment 0010d.2 – E144 RWS Bkup Batteries-FMECA.xlsx XLSX spreadsheet
Attachment 0010d.5 – E152 – Media Converter 05-FMECA.xlsx XLSX spreadsheet
Attachment 0010d.9 - E156 UPS - FMECA.xlsx XLSX spreadsheet
Attachment 0010e.2 – E082 thru E091 Wkstn Laptop-FMECA.xlsx XLSX spreadsheet
Attachment 0010e.4 – E102d thru E111 Vid Extender-FMECA.xlsx XLSX spreadsheet
Attachment 0010e.8 – E146 – Table 2 Assembly-FMECA.xlsx XLSX spreadsheet
Show all 50

RFP for Integrated Battle Command System (IBCS) LRIP/FRP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

POA&M

***** UNCLASSIFIED//FOR OFFICIAL USE ONLY *****
Date Exported:System Type:OMB Project ID:
Exported By:
DoD Component:POC Name:
System / Project Name:POC Phone:Security Costs:
DoD IT Registration No:POC E-Mail:
Control Vulnerability DescriptionPOA&M Item IDControl Vulnerability DescriptionSecurity Control Number (NC/NA controls only)Office/OrgSecurity ChecksResources RequiredScheduled Completion DateMilestone with Completion DatesMilestone ChangesSource Identifying VulnerabilityStatusCommentsRaw SeverityMitigationsSeverityRelevance of ThreatLikelihoodImpactImpact DescriptionResidual Risk LevelRecommendations

&B &14 &"Arial"&K007A3D ***** UNCLASSIFIED//FOR OFFICIAL USE ONLY *****

&B &14 &"Arial"&K007A3D ***** UNCLASSIFIED//FOR OFFICIAL USE ONLY *****

Sheet1

Very LowCompletedI
LowOngoingII
ModerateNot ApplicableIII
HighArchived
Very HighRisk Accepted
RMF_Standard

8500 IA Controls

MAC I / CLMAC I / SMAC I / PMAC II / CLMAC II / SMAC II / PMAC III - CLMAC III - SMAC III - PIA CONTROLSUBJECT AREATITLEIMPACT CODES
YYYCOAS-1ContinuityAlternate Site DesignationMedium
YYYYYYCOAS-2ContinuityAlternate Site DesignationHigh
YYYYYYYYYCOBR-1ContinuityProtection of Backup and Restoration AssetsHigh
YYYCODB-1ContinuityData Backup ProceduresLow
YYYCODB-2ContinuityData Back-up ProceduresMedium
YYYCODB-3ContinuityData Backup ProceduresMedium
YYYCODP-1ContinuityDisaster and Recovery PlanningLow
YYYCODP-2ContinuityDisaster and Recovery PlanningMedium
YYYCODP-3ContinuityDisaster and Recovery PlanningMedium
YYYYYYCOEB-1ContinuityEnclave Boundary DefenseMedium
YYYCOEB-2ContinuityEnclave Boundary DefenseHigh
YYYYYYCOED-1ContinuityScheduled Exercises and DrillsLow
YYYCOED-2ContinuityScheduled Exercises and DrillsMedium
YYYCOEF-1ContinuityIdentification of Essential FunctionsLow
YYYYYYCOEF-2ContinuityIdentification of Essential FunctionsMedium
YYYCOMS-1ContinuityMaintenance SupportLow
YYYYYYCOMS-2ContinuityMaintenance SupportMedium
YYYCOPS-1ContinuityPower SupplyLow
YYYCOPS-2ContinuityPower SupplyMedium
YYYCOPS-3ContinuityPower SupplyMedium
YYYYYYCOSP-1ContinuitySpares and PartsLow
YYYCOSP-2ContinuitySpares and PartsMedium
YYYYYYYYYCOSW-1ContinuityBackup Copies of Critical SoftwareHigh
YYYYYYYYYCOTR-1ContinuityTrusted RecoveryHigh
YYYYYYYYYDCAR-1Security Design and ConfigurationProcedural ReviewMedium
YYYYYYYYYDCAS-1Security Design and ConfigurationAcquisition StandardsHigh
YYYYYYYYYDCBP-1Security Design and ConfigurationBest Security PracticesMedium
YYYDCCB-1Security Design and ConfigurationControl BoardLow
YYYYYYDCCB-2Security Design and ConfigurationControl BoardMedium
YYYDCCS-1Security Design and ConfigurationConfiguration SpecificationsHigh
YYYYYYDCCS-2Security Design and ConfigurationConfiguration SpecificationsHigh
YYYYYYYYYDCCT-1Security Design and ConfigurationCompliance TestingMedium
YYYYYYYYYDCDS-1Security Design and ConfigurationDedicated IA ServicesMedium
YYYYYYYYYDCFA-1Security Design and ConfigurationFunctional Architecture for AIS ApplicationsMedium
YYYYYYYYYDCHW-1Security Design and ConfigurationHW BaselineHigh
YYYYYYYYYDCID-1Security Design and ConfigurationInterconnection DocumentationHigh
YYYYYYYYYDCII-1Security Design and ConfigurationIA Impact AssessmentMedium
YYYYYYYYYDCIT-1Security Design and ConfigurationIA for IT ServicesHigh
YYYYYYYYYDCMC-1Security Design and ConfigurationMobile CodeMedium
YYYYYYYYYDCNR-1Security Design and ConfigurationNon-repudiationMedium
YYYYYYDCPA-1Security Design and ConfigurationPartitioning the ApplicationLow
YYYYYYDCPB-1Security Design and ConfigurationIA Program and BudgetHigh
YYYYYYYYYDCPD-1Security Design and ConfigurationPublic Domain Software ControlsMedium
YYYYYYYYYDCPP-1Security Design and ConfigurationPorts, Protocols, and ServicesMedium
YYYYYYYYYDCPR-1Security Design and ConfigurationCM ProcessHigh
YYYYYYYYYDCSD-1Security Design and ConfigurationIA DocumentationHigh
YYYYYYYYYDCSL-1Security Design and ConfigurationSystem Library Management ControlsMedium
YYYYYYDCSP-1Security Design and ConfigurationSecurity Support Structure PartitioningMedium
YYYYYYYYYDCSQ-1Security Design and ConfigurationSoftware QualityMedium
YYYDCSR-1Security Design and ConfigurationSpecified Robustness - BasicHigh
YYYDCSR-2Security Design and ConfigurationSpecified Robustness - MediumHigh
YYYDCSR-3Security Design and ConfigurationSpecified Robustness – HighHigh
YYDCSS-1Security Design and ConfigurationSystem State ChangesHigh
YYYYYYYDCSS-2Security Design and ConfigurationSystem State ChangesHigh
YYYYYYYYYDCSW-1Security Design and ConfigurationSW BaselineHigh
YYYEBBD-1Enclave and Computing EnvironmentBoundary DefenseLow
YYYEBBD-2Enclave and Computing EnvironmentBoundary DefenseMedium
YYYEBBD-3Enclave and Computing EnvironmentBoundary DefenseHigh
YYYYYYYYYEBCR-1Enclave and Computing EnvironmentConnection RulesMedium
YYYYYYEBPW-1Enclave and Computing EnvironmentPublic WAN ConnectionHigh
YYYYYYEBRP-1Enclave and Computing EnvironmentRemote Access for Privileged FunctionsHigh
YYYYYYEBRU-1Enclave and Computing EnvironmentRemote Access for User FunctionsHigh
YYYYYYYYYEBVC-1Enclave and Computing EnvironmentVPN ControlsMedium
YYYYYYECAD-1Enclave and Computing EnvironmentAffiliation DisplayMedium
YYYYYYECAN-1Enclave and Computing EnvironmentAccess for Need-to-KnowHigh
YYYECAR-1Enclave and Computing EnvironmentAudit Record ContentLow
YYYECAR-2Enclave and Computing EnvironmentAudit Record ContentMedium
YYYECAR-3Enclave and Computing EnvironmentAudit Record ContentHigh
YYECAT-1Enclave and Computing EnvironmentAudit Trail, Monitoring, Analysis and ReportingLow
YYYYYYYECAT-2Enclave and Computing EnvironmentAudit Trail, Monitoring, Analysis and ReportingMedium
YYECCD-1Enclave and Computing EnvironmentChanges to DataMedium
YYYYYYYECCD-2Enclave and Computing EnvironmentChanges to DataHigh
YYYECCM-1Enclave and Computing EnvironmentCOMSECHigh
YYYECCR-1Enclave and Computing EnvironmentEncryption for Confidentiality (Data at Rest)Low
YYYECCR-2Enclave and Computing EnvironmentEncryption for Confidentiality (Data at Rest)Medium
YYYECCR-3Enclave and Computing EnvironmentEncryption for Confidentiality (Data at Rest)High
YYYECCT-1Enclave and Computing EnvironmentEncryption for Confidentiality (Data in Transit)Medium
YYYECCT-2Enclave and Computing EnvironmentEncryption for Confidentiality (Data in Transit)High
YYYYYYECDC-1Enclave and Computing EnvironmentData Change ControlsMedium
YYYYYYECIC-1Enclave and Computing EnvironmentInterconnection among DoD Systems and EnclavesMedium
YYYYYYECID-1Enclave and Computing EnvironmentHost Based IDSMedium
YYYYYYYYYECIM-1Enclave and Computing EnvironmentInstant MessagingMedium
YYYECLC-1Enclave and Computing EnvironmentAudit of Security Label ChangesLow
YYYECLO-1Enclave and Computing EnvironmentLogonMedium
YYYECLO-2Enclave and Computing EnvironmentLogonMedium
YYYYYYYYYECLP-1Enclave and Computing EnvironmentLeast PrivilegeHigh
YYYYYYECML-1Enclave and Computing EnvironmentMarking and LabelingHigh
YYYYYYECMT-1Enclave and Computing EnvironmentConformance Monitoring and TestingLow
YYYECMT-2Enclave and Computing EnvironmentConformance Monitoring and TestingMedium
YYYECND-1Enclave and Computing EnvironmentNetwork Device ControlsLow
YYYYYYECND-2Enclave and Computing EnvironmentNetwork Device ControlsMedium
YYYYYYECNK-1Enclave and Computing EnvironmentEncryption for Need-To-KnowMedium
YYYECNK-2Enclave and Computing EnvironmentEncryption for Need-To-KnowMedium
YYYYYYYYYECPA-1Enclave and Computing EnvironmentPrivileged Account ControlHigh
YYYECPC-1Enclave and Computing EnvironmentProduction Code Change ControlsMedium
YYYYYYECPC-2Enclave and Computing EnvironmentProduction Code Change ControlsMedium
YYYYYYECRC-1Enclave and Computing EnvironmentResource ControlMedium
YYYYYYYYYECRG-1Enclave and Computing EnvironmentAudit Reduction and Report GenerationLow
YYYYYYYYYECRR-1Enclave and Computing EnvironmentAudit Record RetentionMedium
YYYYYYYYYECSC-1Enclave and Computing EnvironmentSecurity Configuration ComplianceHigh
YYYECSD-1Enclave and Computing EnvironmentSoftware Development Change ControlsMedium
YYYYYYECSD-2Enclave and Computing EnvironmentSoftware Development Change ControlsHigh
YYYYYYYECTB-1Enclave and Computing EnvironmentAudit Trail BackupMedium
YYYYYYECTC-1Enclave and Computing EnvironmentTempest ControlsHigh
YYYECTM-1Enclave and Computing EnvironmentTransmission Integrity ControlsMedium
YYYYYYECTM-2Enclave and Computing EnvironmentTransmission Integrity ControlsMedium
YYYYYYYYYECTP-1Enclave and Computing EnvironmentAudit Trail ProtectionMedium
YYYYYYYYYECVI-1Enclave and Computing EnvironmentVoice over IPMedium
YYYYYYYYYECVP-1Enclave and Computing EnvironmentVirus ProtectionHigh
YYYYYYYYYECWM-1Enclave and Computing EnvironmentWarning MessageLow
YYYYYYYYYECWN-1Enclave and Computing EnvironmentWireless Computing and NetworkingHigh
YYYYYYIAAC-1Enclave and Computing EnvironmentAccount ControlHigh
YYYYYYIAGA-1Identification and AuthenticationGroup Identification and AuthenticationMedium
YYYIAIA-1Identification and AuthenticationIndividual Identification and AuthenticationHigh
YYYIAIA-2Identification and AuthenticationIndividual Identification and AuthenticationHigh
YYIAKM-1Identification and AuthenticationKey ManagementMedium
YYYYIAKM-2Identification and AuthenticationKey ManagementMedium
YYYIAKM-3Identification and AuthenticationKey ManagementMedium
YYYIATS-1Identification and AuthenticationToken and Certificate StandardsMedium
YYYYYYIATS-2Identification and AuthenticationToken and Certificate StandardsMedium
YYYPECF-1Physical and EnvironmentalAccess to Computing FacilitiesHigh
YYYPECF-2Physical and EnvironmentalAccess to Computing FacilitiesHigh
YYYPECS-1Physical and EnvironmentalClearing and SanitizingHigh
YYYPECS-2Physical and EnvironmentalClearing and SanitizingHigh
YYYPEDD-1Physical and EnvironmentalDestructionHigh
YYYYYYPEDI-1Physical and EnvironmentalData InterceptionHigh
YYYPEEL-1Physical and EnvironmentalEmergency LightingLow
YYYYYYPEEL-2Physical and EnvironmentalEmergency LightingMedium
YYYPEFD-1Physical and EnvironmentalFire DetectionHigh
YYYYYYPEFD-2Physical and EnvironmentalFire DetectionHigh
YYYYYYYYYPEFI-1Physical and EnvironmentalFire InspectionMedium
YYYPEFS-1Physical and EnvironmentalFire Suppression SystemMedium
YYYYYYPEFS-2Physical and EnvironmentalFire Suppression SystemHigh
YYYPEHC-1Physical and EnvironmentalHumidity ControlsMedium
YYYYYYPEHC-2Physical and EnvironmentalHumidity ControlsMedium
YYYYYYYYYPEMS-1Physical and EnvironmentalMaster Power SwitchHigh
YYYPEPF-1Physical and EnvironmentalPhysical Protection of FacilitiesHigh
YYYPEPF-2Physical and EnvironmentalPhysical Protection of FacilitiesHigh
YYYYYYPEPS-1Physical and EnvironmentalPhysical Security TestingLow
YYYYYYYYYPESL-1Physical and EnvironmentalScreen LockMedium
YYYYYYPESP-1Physical and EnvironmentalWorkplace Security ProceduresMedium
YYYYYYPESS-1Physical and EnvironmentalStorageHigh
YYYPETC-1Physical and EnvironmentalTemperature ControlsLow
YYYYYYPETC-2Physical and EnvironmentalTemperature ControlsMedium
YYYYYYYYYPETN-1Physical and EnvironmentalEnvironmental Control TrainingLow
YYYYYYPEVC-1Physical and EnvironmentalVisitor Control to Computing FacilitiesHigh
YYYYYYYYYPEVR-1Physical and EnvironmentalVoltage RegulatorsHigh
YYYPRAS-1PersonnelAccess to InformationHigh
YYYPRAS-2PersonnelAccess to InformationHigh
YYYYYYPRMP-1PersonnelMaintenance PersonnelHigh
YYYPRMP-2PersonnelMaintenance PersonnelHigh
YYYYYYYYYPRNK-1PersonnelAccess to Need-to-Know InformationHigh
YYYYYYYYYPRRB-1PersonnelSecurity Rules of Behavior or Acceptable Use PolicyHigh
YYYYYYPRTN-1PersonnelInformation Assurance TrainingHigh
YYYYYYVIIR-1Vulnerabiity and Incident ManagementIncident Response PlanningMedium
YYYVIIR-2Vulnerabiity and Incident ManagementIncident Response PlanningHigh
YYYYYYYYYVIVM-1Vulnerabiity and Incident ManagementVulnerability ManagementMedium
110106811101068110510075

Example

***** UNCLASSIFIED//FOR OFFICIAL USE ONLY *****
Date Exported:2/20/2018System Type:IS EnclaveOMB Project ID:54324
Exported By:John Smith
DoD Component:DoDPOC Name:John Smith
System / Project Name:First SystemPOC Phone:747-380-0987Security Costs:$10,000
DoD IT Registration No:5050POC E-Mail:john.smith@mail.mil
POA&M Item IDControl Vulnerability DescriptionSecurity Control Number (NC/NA controls only)Office/OrgSecurity ChecksResources RequiredScheduled Completion DateMilestone with Completion DatesMilestone ChangesSource Identifying VulnerabilityStatusCommentsRaw SeverityMitigationsSeverityRelevance of ThreatLikelihoodImpactImpact DescriptionResidual Risk LevelRecommendations
1Description that explains the identified vulnerability and any other pertinent information.AC-1DoD, John Smith, 7033775472, smith_john@email.comSV-18394r2_ruleResources required to correct the identified vulnerability.11/23/18Implement Procedure A 10/25/2018Narrative description of how this vulnerability was discovered (annual review, automated scan, etc.)OngoingDescription of any relevant information not captured by the other fields.IDescription of the mitigations in place (if any) to counter this vulnerability.HighHighHighHighDescription of magnitude of potential harm from the exploitation of this vulnerability.HighSummary of the recommended actions that will further address/reduce the risk of this vulnerability.
Implement Procedure B 10/31/2018
Implement Procedure C 11/5/2018
2Description that explains the identified vulnerability and any other pertinent information.SA-1.4DoDSV-40098r2_ruleResources required to correct the identified vulnerability.Narrative description of how this vulnerability was discovered (annual review, automated scan, etc.)Risk AcceptedDescription of any relevant information not captured by the other fields.IIIDescription of the mitigations in place (if any) to counter this vulnerability.Very LowLowVery LowModerateDescription of magnitude of potential harm from the exploitation of this vulnerability.LowSummary of the recommended actions that will further address/reduce the risk of this vulnerability.
3Description that explains the identified vulnerability and any other pertinent information.Example Program Management OfficeResources required to correct the identified vulnerability.10/25/18Description of Milestone 10/17/2018Updated Milestone Description 10/22/2018Narrative description of how this vulnerability was discovered (annual review, automated scan, etc.)Completed 11/13/2018Description of any relevant information not captured by the other fields.IIIDescription of the mitigations in place (if any) to counter this vulnerability.HighModerateModerateHighDescription of magnitude of potential harm from the exploitation of this vulnerability.ModerateSummary of the recommended actions that will further address/reduce the risk of this vulnerability.

mailto:smith_john@email.commailto:john.smith@mail.mil Instructions

POA&M Template Instructions
1. This POA&M Template is intended for RMF Systems only. If documenting POA&M Items for a DIACAP System, please download the DIACAP POA&M Template available on the eMASS Help page.
2. Enter valid information into the fields on the POA&M Template.
3. The POA&M Item ID is automatically generated by eMASS after the POA&M Item is successfully imported. No user action is required to complete or update and therefore this column can be treated as read-only.
4. Do not delete columns/sheets, delete the classification label, or add additional columns. Doing so may have a negative impact on the ability for eMASS to ingest the template.
5. To import a System-level POA&M Item, the Security Control Number field must be left blank.
6. To import a Control-level POA&M Item, enter the appropriate Control Acronym (e.g., AC-3) into the Security Control Number field.
7. To import an Assessment Procedure-level POA&M Item, enter the appropriate AP Acronym (e.g., AC-3.1) into the Security Control Number field.
8. When entering Office/Org, enter Organization, First Name Last Name, Phone Number, Email. At a minimum, the Office/Org must be defined for each POA&M Item. If multiple fields are entered, ensure each field is separated by a comma. Do not separate first and last name with a comma.
9. Security Checks (optional field) can be populated with DISA Security Technical Implementation Guide (STIG) rules (i.e. SV-40098r2_rule), USCYBERCOM IAVM IDs, or ACAS Plugin IDs.
10. When listing multiple Security Checks for a specific POA&M Item, separate each Security Check by a semicolon.
11. If a POA&M Item has multiple milestones, each milestone must be entered in separate rows within the Milestone w/Completion Date field.
12. If a POA&M Item has multiple milestone changes, each milestone change must be entered chronologically in separate rows within the Milestone Changes field.
13. For unapproved POA&M Items, the Milestone Scheduled Completion Date cannot exceed that of the overall Scheduled Completion Date. For POA&M Items that have a Review Status of "Approved" in eMASS, a Milestone Scheduled Completion Date can be set beyond that of the overall Scheduled Completion Date to create a pending Extension Date.
14. To add a new milestone to an existing POA&M Item, insert a new row after the last existing milestone for the applicable POA&M. Information entered into that row will be used to populate the new milestone upon import.
15. Dates in the Status (for Completed & AO Approved Risk Accepted POA&M Items), Milestones w/Completion Dates, and Milestone Changes field must be entered after text.
16. Raw Severity (optional field) can be populated with values of I, II, or, III. Raw Severity values are typically defined for vulnerablities related to DISA STIG Security Checks.
17. Expected values for the optional fields of Severity, Relevance of Threat, Likelihood, Impact, and Residual Risk Level are Very Low, Low, Moderate, High, or Very High.
18. Values for the optional fields of Impact and Residual Risk Level should be reflective of the DoD-defined risk calculation matrixes in Tables 8 and 9 on the RMF Knowledge Service (https://rmfks.osd.mil/rmf/RMFImplementation/AssessControls/Pages/ResidualRisk.aspx).
19. For Ongoing POA&M Items, the Status, Scheduled Completion Date, Office/Organization, Vulnerability Description, and Source Identifying Vulnerability act as required fields. For Completed and Risk Accepted POA&M Items, the Comments field is also required.
20. If updating existing POA&M Item and/or milestone information, ensure that those changes are being applied to the latest version of each POA&M Item. Export the latest copy of applicable POA&M Items via the POA&M Import page in eMASS.

File details come from the government source that posted it. Updated .