Attachment 0030 - POAMImportTemplate RM Standard.xlsm.xlsx
XLSX spreadsheet 74 KB Posted
- Attached to
- RFP for Integrated Battle Command System (IBCS) LRIP/FRP Federal contract opportunity
- Solicitation number
- W31P4Q-20-R-0015
About this file
This document contains a Plan of Action and Milestones (POA&M) template for documenting vulnerabilities and corrective actions related to Risk Management Framework systems. The template includes fields for capturing the POA&M item ID, security control information, office and point of contact details, resources required, scheduled completion dates, milestones, status updates, severity ratings, and recommended actions. Instructions are provided on how to populate the fields to import POA&M items into an automated system. The template does not specify any required products or services but rather provides a standardized means of documenting vulnerability remediation plans according to Risk Management Framework requirements.
View the file
Other files for this federal contract opportunity
Show all 50
RFP for Integrated Battle Command System (IBCS) LRIP/FRP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
POA&M
| ***** UNCLASSIFIED//FOR OFFICIAL USE ONLY ***** | |||||||||||||||||||||
| Date Exported: | System Type: | OMB Project ID: | |||||||||||||||||||
| Exported By: | |||||||||||||||||||||
| DoD Component: | POC Name: | ||||||||||||||||||||
| System / Project Name: | POC Phone: | Security Costs: | |||||||||||||||||||
| DoD IT Registration No: | POC E-Mail: | ||||||||||||||||||||
| Control Vulnerability Description | POA&M Item ID | Control Vulnerability Description | Security Control Number (NC/NA controls only) | Office/Org | Security Checks | Resources Required | Scheduled Completion Date | Milestone with Completion Dates | Milestone Changes | Source Identifying Vulnerability | Status | Comments | Raw Severity | Mitigations | Severity | Relevance of Threat | Likelihood | Impact | Impact Description | Residual Risk Level | Recommendations |
&B &14 &"Arial"&K007A3D ***** UNCLASSIFIED//FOR OFFICIAL USE ONLY *****
&B &14 &"Arial"&K007A3D ***** UNCLASSIFIED//FOR OFFICIAL USE ONLY *****
Sheet1
| Very Low | Completed | I |
| Low | Ongoing | II |
| Moderate | Not Applicable | III |
| High | Archived | |
| Very High | Risk Accepted | |
| RMF_Standard |
8500 IA Controls
| MAC I / CL | MAC I / S | MAC I / P | MAC II / CL | MAC II / S | MAC II / P | MAC III - CL | MAC III - S | MAC III - P | IA CONTROL | SUBJECT AREA | TITLE | IMPACT CODES |
| Y | Y | Y | COAS-1 | Continuity | Alternate Site Designation | Medium | ||||||
| Y | Y | Y | Y | Y | Y | COAS-2 | Continuity | Alternate Site Designation | High | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | COBR-1 | Continuity | Protection of Backup and Restoration Assets | High |
| Y | Y | Y | CODB-1 | Continuity | Data Backup Procedures | Low | ||||||
| Y | Y | Y | CODB-2 | Continuity | Data Back-up Procedures | Medium | ||||||
| Y | Y | Y | CODB-3 | Continuity | Data Backup Procedures | Medium | ||||||
| Y | Y | Y | CODP-1 | Continuity | Disaster and Recovery Planning | Low | ||||||
| Y | Y | Y | CODP-2 | Continuity | Disaster and Recovery Planning | Medium | ||||||
| Y | Y | Y | CODP-3 | Continuity | Disaster and Recovery Planning | Medium | ||||||
| Y | Y | Y | Y | Y | Y | COEB-1 | Continuity | Enclave Boundary Defense | Medium | |||
| Y | Y | Y | COEB-2 | Continuity | Enclave Boundary Defense | High | ||||||
| Y | Y | Y | Y | Y | Y | COED-1 | Continuity | Scheduled Exercises and Drills | Low | |||
| Y | Y | Y | COED-2 | Continuity | Scheduled Exercises and Drills | Medium | ||||||
| Y | Y | Y | COEF-1 | Continuity | Identification of Essential Functions | Low | ||||||
| Y | Y | Y | Y | Y | Y | COEF-2 | Continuity | Identification of Essential Functions | Medium | |||
| Y | Y | Y | COMS-1 | Continuity | Maintenance Support | Low | ||||||
| Y | Y | Y | Y | Y | Y | COMS-2 | Continuity | Maintenance Support | Medium | |||
| Y | Y | Y | COPS-1 | Continuity | Power Supply | Low | ||||||
| Y | Y | Y | COPS-2 | Continuity | Power Supply | Medium | ||||||
| Y | Y | Y | COPS-3 | Continuity | Power Supply | Medium | ||||||
| Y | Y | Y | Y | Y | Y | COSP-1 | Continuity | Spares and Parts | Low | |||
| Y | Y | Y | COSP-2 | Continuity | Spares and Parts | Medium | ||||||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | COSW-1 | Continuity | Backup Copies of Critical Software | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | COTR-1 | Continuity | Trusted Recovery | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCAR-1 | Security Design and Configuration | Procedural Review | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCAS-1 | Security Design and Configuration | Acquisition Standards | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCBP-1 | Security Design and Configuration | Best Security Practices | Medium |
| Y | Y | Y | DCCB-1 | Security Design and Configuration | Control Board | Low | ||||||
| Y | Y | Y | Y | Y | Y | DCCB-2 | Security Design and Configuration | Control Board | Medium | |||
| Y | Y | Y | DCCS-1 | Security Design and Configuration | Configuration Specifications | High | ||||||
| Y | Y | Y | Y | Y | Y | DCCS-2 | Security Design and Configuration | Configuration Specifications | High | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCCT-1 | Security Design and Configuration | Compliance Testing | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCDS-1 | Security Design and Configuration | Dedicated IA Services | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCFA-1 | Security Design and Configuration | Functional Architecture for AIS Applications | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCHW-1 | Security Design and Configuration | HW Baseline | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCID-1 | Security Design and Configuration | Interconnection Documentation | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCII-1 | Security Design and Configuration | IA Impact Assessment | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCIT-1 | Security Design and Configuration | IA for IT Services | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCMC-1 | Security Design and Configuration | Mobile Code | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCNR-1 | Security Design and Configuration | Non-repudiation | Medium |
| Y | Y | Y | Y | Y | Y | DCPA-1 | Security Design and Configuration | Partitioning the Application | Low | |||
| Y | Y | Y | Y | Y | Y | DCPB-1 | Security Design and Configuration | IA Program and Budget | High | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCPD-1 | Security Design and Configuration | Public Domain Software Controls | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCPP-1 | Security Design and Configuration | Ports, Protocols, and Services | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCPR-1 | Security Design and Configuration | CM Process | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCSD-1 | Security Design and Configuration | IA Documentation | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCSL-1 | Security Design and Configuration | System Library Management Controls | Medium |
| Y | Y | Y | Y | Y | Y | DCSP-1 | Security Design and Configuration | Security Support Structure Partitioning | Medium | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCSQ-1 | Security Design and Configuration | Software Quality | Medium |
| Y | Y | Y | DCSR-1 | Security Design and Configuration | Specified Robustness - Basic | High | ||||||
| Y | Y | Y | DCSR-2 | Security Design and Configuration | Specified Robustness - Medium | High | ||||||
| Y | Y | Y | DCSR-3 | Security Design and Configuration | Specified Robustness – High | High | ||||||
| Y | Y | DCSS-1 | Security Design and Configuration | System State Changes | High | |||||||
| Y | Y | Y | Y | Y | Y | Y | DCSS-2 | Security Design and Configuration | System State Changes | High | ||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | DCSW-1 | Security Design and Configuration | SW Baseline | High |
| Y | Y | Y | EBBD-1 | Enclave and Computing Environment | Boundary Defense | Low | ||||||
| Y | Y | Y | EBBD-2 | Enclave and Computing Environment | Boundary Defense | Medium | ||||||
| Y | Y | Y | EBBD-3 | Enclave and Computing Environment | Boundary Defense | High | ||||||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | EBCR-1 | Enclave and Computing Environment | Connection Rules | Medium |
| Y | Y | Y | Y | Y | Y | EBPW-1 | Enclave and Computing Environment | Public WAN Connection | High | |||
| Y | Y | Y | Y | Y | Y | EBRP-1 | Enclave and Computing Environment | Remote Access for Privileged Functions | High | |||
| Y | Y | Y | Y | Y | Y | EBRU-1 | Enclave and Computing Environment | Remote Access for User Functions | High | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | EBVC-1 | Enclave and Computing Environment | VPN Controls | Medium |
| Y | Y | Y | Y | Y | Y | ECAD-1 | Enclave and Computing Environment | Affiliation Display | Medium | |||
| Y | Y | Y | Y | Y | Y | ECAN-1 | Enclave and Computing Environment | Access for Need-to-Know | High | |||
| Y | Y | Y | ECAR-1 | Enclave and Computing Environment | Audit Record Content | Low | ||||||
| Y | Y | Y | ECAR-2 | Enclave and Computing Environment | Audit Record Content | Medium | ||||||
| Y | Y | Y | ECAR-3 | Enclave and Computing Environment | Audit Record Content | High | ||||||
| Y | Y | ECAT-1 | Enclave and Computing Environment | Audit Trail, Monitoring, Analysis and Reporting | Low | |||||||
| Y | Y | Y | Y | Y | Y | Y | ECAT-2 | Enclave and Computing Environment | Audit Trail, Monitoring, Analysis and Reporting | Medium | ||
| Y | Y | ECCD-1 | Enclave and Computing Environment | Changes to Data | Medium | |||||||
| Y | Y | Y | Y | Y | Y | Y | ECCD-2 | Enclave and Computing Environment | Changes to Data | High | ||
| Y | Y | Y | ECCM-1 | Enclave and Computing Environment | COMSEC | High | ||||||
| Y | Y | Y | ECCR-1 | Enclave and Computing Environment | Encryption for Confidentiality (Data at Rest) | Low | ||||||
| Y | Y | Y | ECCR-2 | Enclave and Computing Environment | Encryption for Confidentiality (Data at Rest) | Medium | ||||||
| Y | Y | Y | ECCR-3 | Enclave and Computing Environment | Encryption for Confidentiality (Data at Rest) | High | ||||||
| Y | Y | Y | ECCT-1 | Enclave and Computing Environment | Encryption for Confidentiality (Data in Transit) | Medium | ||||||
| Y | Y | Y | ECCT-2 | Enclave and Computing Environment | Encryption for Confidentiality (Data in Transit) | High | ||||||
| Y | Y | Y | Y | Y | Y | ECDC-1 | Enclave and Computing Environment | Data Change Controls | Medium | |||
| Y | Y | Y | Y | Y | Y | ECIC-1 | Enclave and Computing Environment | Interconnection among DoD Systems and Enclaves | Medium | |||
| Y | Y | Y | Y | Y | Y | ECID-1 | Enclave and Computing Environment | Host Based IDS | Medium | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECIM-1 | Enclave and Computing Environment | Instant Messaging | Medium |
| Y | Y | Y | ECLC-1 | Enclave and Computing Environment | Audit of Security Label Changes | Low | ||||||
| Y | Y | Y | ECLO-1 | Enclave and Computing Environment | Logon | Medium | ||||||
| Y | Y | Y | ECLO-2 | Enclave and Computing Environment | Logon | Medium | ||||||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECLP-1 | Enclave and Computing Environment | Least Privilege | High |
| Y | Y | Y | Y | Y | Y | ECML-1 | Enclave and Computing Environment | Marking and Labeling | High | |||
| Y | Y | Y | Y | Y | Y | ECMT-1 | Enclave and Computing Environment | Conformance Monitoring and Testing | Low | |||
| Y | Y | Y | ECMT-2 | Enclave and Computing Environment | Conformance Monitoring and Testing | Medium | ||||||
| Y | Y | Y | ECND-1 | Enclave and Computing Environment | Network Device Controls | Low | ||||||
| Y | Y | Y | Y | Y | Y | ECND-2 | Enclave and Computing Environment | Network Device Controls | Medium | |||
| Y | Y | Y | Y | Y | Y | ECNK-1 | Enclave and Computing Environment | Encryption for Need-To-Know | Medium | |||
| Y | Y | Y | ECNK-2 | Enclave and Computing Environment | Encryption for Need-To-Know | Medium | ||||||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECPA-1 | Enclave and Computing Environment | Privileged Account Control | High |
| Y | Y | Y | ECPC-1 | Enclave and Computing Environment | Production Code Change Controls | Medium | ||||||
| Y | Y | Y | Y | Y | Y | ECPC-2 | Enclave and Computing Environment | Production Code Change Controls | Medium | |||
| Y | Y | Y | Y | Y | Y | ECRC-1 | Enclave and Computing Environment | Resource Control | Medium | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECRG-1 | Enclave and Computing Environment | Audit Reduction and Report Generation | Low |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECRR-1 | Enclave and Computing Environment | Audit Record Retention | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECSC-1 | Enclave and Computing Environment | Security Configuration Compliance | High |
| Y | Y | Y | ECSD-1 | Enclave and Computing Environment | Software Development Change Controls | Medium | ||||||
| Y | Y | Y | Y | Y | Y | ECSD-2 | Enclave and Computing Environment | Software Development Change Controls | High | |||
| Y | Y | Y | Y | Y | Y | Y | ECTB-1 | Enclave and Computing Environment | Audit Trail Backup | Medium | ||
| Y | Y | Y | Y | Y | Y | ECTC-1 | Enclave and Computing Environment | Tempest Controls | High | |||
| Y | Y | Y | ECTM-1 | Enclave and Computing Environment | Transmission Integrity Controls | Medium | ||||||
| Y | Y | Y | Y | Y | Y | ECTM-2 | Enclave and Computing Environment | Transmission Integrity Controls | Medium | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECTP-1 | Enclave and Computing Environment | Audit Trail Protection | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECVI-1 | Enclave and Computing Environment | Voice over IP | Medium |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECVP-1 | Enclave and Computing Environment | Virus Protection | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECWM-1 | Enclave and Computing Environment | Warning Message | Low |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | ECWN-1 | Enclave and Computing Environment | Wireless Computing and Networking | High |
| Y | Y | Y | Y | Y | Y | IAAC-1 | Enclave and Computing Environment | Account Control | High | |||
| Y | Y | Y | Y | Y | Y | IAGA-1 | Identification and Authentication | Group Identification and Authentication | Medium | |||
| Y | Y | Y | IAIA-1 | Identification and Authentication | Individual Identification and Authentication | High | ||||||
| Y | Y | Y | IAIA-2 | Identification and Authentication | Individual Identification and Authentication | High | ||||||
| Y | Y | IAKM-1 | Identification and Authentication | Key Management | Medium | |||||||
| Y | Y | Y | Y | IAKM-2 | Identification and Authentication | Key Management | Medium | |||||
| Y | Y | Y | IAKM-3 | Identification and Authentication | Key Management | Medium | ||||||
| Y | Y | Y | IATS-1 | Identification and Authentication | Token and Certificate Standards | Medium | ||||||
| Y | Y | Y | Y | Y | Y | IATS-2 | Identification and Authentication | Token and Certificate Standards | Medium | |||
| Y | Y | Y | PECF-1 | Physical and Environmental | Access to Computing Facilities | High | ||||||
| Y | Y | Y | PECF-2 | Physical and Environmental | Access to Computing Facilities | High | ||||||
| Y | Y | Y | PECS-1 | Physical and Environmental | Clearing and Sanitizing | High | ||||||
| Y | Y | Y | PECS-2 | Physical and Environmental | Clearing and Sanitizing | High | ||||||
| Y | Y | Y | PEDD-1 | Physical and Environmental | Destruction | High | ||||||
| Y | Y | Y | Y | Y | Y | PEDI-1 | Physical and Environmental | Data Interception | High | |||
| Y | Y | Y | PEEL-1 | Physical and Environmental | Emergency Lighting | Low | ||||||
| Y | Y | Y | Y | Y | Y | PEEL-2 | Physical and Environmental | Emergency Lighting | Medium | |||
| Y | Y | Y | PEFD-1 | Physical and Environmental | Fire Detection | High | ||||||
| Y | Y | Y | Y | Y | Y | PEFD-2 | Physical and Environmental | Fire Detection | High | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PEFI-1 | Physical and Environmental | Fire Inspection | Medium |
| Y | Y | Y | PEFS-1 | Physical and Environmental | Fire Suppression System | Medium | ||||||
| Y | Y | Y | Y | Y | Y | PEFS-2 | Physical and Environmental | Fire Suppression System | High | |||
| Y | Y | Y | PEHC-1 | Physical and Environmental | Humidity Controls | Medium | ||||||
| Y | Y | Y | Y | Y | Y | PEHC-2 | Physical and Environmental | Humidity Controls | Medium | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PEMS-1 | Physical and Environmental | Master Power Switch | High |
| Y | Y | Y | PEPF-1 | Physical and Environmental | Physical Protection of Facilities | High | ||||||
| Y | Y | Y | PEPF-2 | Physical and Environmental | Physical Protection of Facilities | High | ||||||
| Y | Y | Y | Y | Y | Y | PEPS-1 | Physical and Environmental | Physical Security Testing | Low | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PESL-1 | Physical and Environmental | Screen Lock | Medium |
| Y | Y | Y | Y | Y | Y | PESP-1 | Physical and Environmental | Workplace Security Procedures | Medium | |||
| Y | Y | Y | Y | Y | Y | PESS-1 | Physical and Environmental | Storage | High | |||
| Y | Y | Y | PETC-1 | Physical and Environmental | Temperature Controls | Low | ||||||
| Y | Y | Y | Y | Y | Y | PETC-2 | Physical and Environmental | Temperature Controls | Medium | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PETN-1 | Physical and Environmental | Environmental Control Training | Low |
| Y | Y | Y | Y | Y | Y | PEVC-1 | Physical and Environmental | Visitor Control to Computing Facilities | High | |||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PEVR-1 | Physical and Environmental | Voltage Regulators | High |
| Y | Y | Y | PRAS-1 | Personnel | Access to Information | High | ||||||
| Y | Y | Y | PRAS-2 | Personnel | Access to Information | High | ||||||
| Y | Y | Y | Y | Y | Y | PRMP-1 | Personnel | Maintenance Personnel | High | |||
| Y | Y | Y | PRMP-2 | Personnel | Maintenance Personnel | High | ||||||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PRNK-1 | Personnel | Access to Need-to-Know Information | High |
| Y | Y | Y | Y | Y | Y | Y | Y | Y | PRRB-1 | Personnel | Security Rules of Behavior or Acceptable Use Policy | High |
| Y | Y | Y | Y | Y | Y | PRTN-1 | Personnel | Information Assurance Training | High | |||
| Y | Y | Y | Y | Y | Y | VIIR-1 | Vulnerabiity and Incident Management | Incident Response Planning | Medium | |||
| Y | Y | Y | VIIR-2 | Vulnerabiity and Incident Management | Incident Response Planning | High | ||||||
| Y | Y | Y | Y | Y | Y | Y | Y | Y | VIVM-1 | Vulnerabiity and Incident Management | Vulnerability Management | Medium |
| 110 | 106 | 81 | 110 | 106 | 81 | 105 | 100 | 75 |
Example
| ***** UNCLASSIFIED//FOR OFFICIAL USE ONLY ***** | |||||||||||||||||||||
| Date Exported: | 2/20/2018 | System Type: | IS Enclave | OMB Project ID: | 54324 | ||||||||||||||||
| Exported By: | John Smith | ||||||||||||||||||||
| DoD Component: | DoD | POC Name: | John Smith | ||||||||||||||||||
| System / Project Name: | First System | POC Phone: | 747-380-0987 | Security Costs: | $10,000 | ||||||||||||||||
| DoD IT Registration No: | 5050 | POC E-Mail: | john.smith@mail.mil | ||||||||||||||||||
| POA&M Item ID | Control Vulnerability Description | Security Control Number (NC/NA controls only) | Office/Org | Security Checks | Resources Required | Scheduled Completion Date | Milestone with Completion Dates | Milestone Changes | Source Identifying Vulnerability | Status | Comments | Raw Severity | Mitigations | Severity | Relevance of Threat | Likelihood | Impact | Impact Description | Residual Risk Level | Recommendations | |
| 1 | Description that explains the identified vulnerability and any other pertinent information. | AC-1 | DoD, John Smith, 7033775472, smith_john@email.com | SV-18394r2_rule | Resources required to correct the identified vulnerability. | 11/23/18 | Implement Procedure A 10/25/2018 | Narrative description of how this vulnerability was discovered (annual review, automated scan, etc.) | Ongoing | Description of any relevant information not captured by the other fields. | I | Description of the mitigations in place (if any) to counter this vulnerability. | High | High | High | High | Description of magnitude of potential harm from the exploitation of this vulnerability. | High | Summary of the recommended actions that will further address/reduce the risk of this vulnerability. | ||
| Implement Procedure B 10/31/2018 | |||||||||||||||||||||
| Implement Procedure C 11/5/2018 | |||||||||||||||||||||
| 2 | Description that explains the identified vulnerability and any other pertinent information. | SA-1.4 | DoD | SV-40098r2_rule | Resources required to correct the identified vulnerability. | Narrative description of how this vulnerability was discovered (annual review, automated scan, etc.) | Risk Accepted | Description of any relevant information not captured by the other fields. | III | Description of the mitigations in place (if any) to counter this vulnerability. | Very Low | Low | Very Low | Moderate | Description of magnitude of potential harm from the exploitation of this vulnerability. | Low | Summary of the recommended actions that will further address/reduce the risk of this vulnerability. | ||||
| 3 | Description that explains the identified vulnerability and any other pertinent information. | Example Program Management Office | Resources required to correct the identified vulnerability. | 10/25/18 | Description of Milestone 10/17/2018 | Updated Milestone Description 10/22/2018 | Narrative description of how this vulnerability was discovered (annual review, automated scan, etc.) | Completed 11/13/2018 | Description of any relevant information not captured by the other fields. | III | Description of the mitigations in place (if any) to counter this vulnerability. | High | Moderate | Moderate | High | Description of magnitude of potential harm from the exploitation of this vulnerability. | Moderate | Summary of the recommended actions that will further address/reduce the risk of this vulnerability. |
mailto:smith_john@email.commailto:john.smith@mail.mil Instructions
| POA&M Template Instructions |
| 1. This POA&M Template is intended for RMF Systems only. If documenting POA&M Items for a DIACAP System, please download the DIACAP POA&M Template available on the eMASS Help page. |
| 2. Enter valid information into the fields on the POA&M Template. |
| 3. The POA&M Item ID is automatically generated by eMASS after the POA&M Item is successfully imported. No user action is required to complete or update and therefore this column can be treated as read-only. |
| 4. Do not delete columns/sheets, delete the classification label, or add additional columns. Doing so may have a negative impact on the ability for eMASS to ingest the template. |
| 5. To import a System-level POA&M Item, the Security Control Number field must be left blank. |
| 6. To import a Control-level POA&M Item, enter the appropriate Control Acronym (e.g., AC-3) into the Security Control Number field. |
| 7. To import an Assessment Procedure-level POA&M Item, enter the appropriate AP Acronym (e.g., AC-3.1) into the Security Control Number field. |
| 8. When entering Office/Org, enter Organization, First Name Last Name, Phone Number, Email. At a minimum, the Office/Org must be defined for each POA&M Item. If multiple fields are entered, ensure each field is separated by a comma. Do not separate first and last name with a comma. |
| 9. Security Checks (optional field) can be populated with DISA Security Technical Implementation Guide (STIG) rules (i.e. SV-40098r2_rule), USCYBERCOM IAVM IDs, or ACAS Plugin IDs. |
| 10. When listing multiple Security Checks for a specific POA&M Item, separate each Security Check by a semicolon. |
| 11. If a POA&M Item has multiple milestones, each milestone must be entered in separate rows within the Milestone w/Completion Date field. |
| 12. If a POA&M Item has multiple milestone changes, each milestone change must be entered chronologically in separate rows within the Milestone Changes field. |
| 13. For unapproved POA&M Items, the Milestone Scheduled Completion Date cannot exceed that of the overall Scheduled Completion Date. For POA&M Items that have a Review Status of "Approved" in eMASS, a Milestone Scheduled Completion Date can be set beyond that of the overall Scheduled Completion Date to create a pending Extension Date. |
| 14. To add a new milestone to an existing POA&M Item, insert a new row after the last existing milestone for the applicable POA&M. Information entered into that row will be used to populate the new milestone upon import. |
| 15. Dates in the Status (for Completed & AO Approved Risk Accepted POA&M Items), Milestones w/Completion Dates, and Milestone Changes field must be entered after text. |
| 16. Raw Severity (optional field) can be populated with values of I, II, or, III. Raw Severity values are typically defined for vulnerablities related to DISA STIG Security Checks. |
| 17. Expected values for the optional fields of Severity, Relevance of Threat, Likelihood, Impact, and Residual Risk Level are Very Low, Low, Moderate, High, or Very High. |
| 18. Values for the optional fields of Impact and Residual Risk Level should be reflective of the DoD-defined risk calculation matrixes in Tables 8 and 9 on the RMF Knowledge Service (https://rmfks.osd.mil/rmf/RMFImplementation/AssessControls/Pages/ResidualRisk.aspx). |
| 19. For Ongoing POA&M Items, the Status, Scheduled Completion Date, Office/Organization, Vulnerability Description, and Source Identifying Vulnerability act as required fields. For Completed and Risk Accepted POA&M Items, the Comments field is also required. |
| 20. If updating existing POA&M Item and/or milestone information, ensure that those changes are being applied to the latest version of each POA&M Item. Export the latest copy of applicable POA&M Items via the POA&M Import page in eMASS. |
File details come from the government source that posted it. Updated .