National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

NIST Special Publication 800-53 (Rev. 4)

Security and Privacy Controls for Federal Information Systems and Organizations

CA-5 PLAN OF ACTION AND MILESTONES

Family:
CA - SECURITY ASSESSMENT AND AUTHORIZATION
Class:
Priority:
P3 - Implement P3 security controls after implementation of P1 and P2 controls.
Baseline Allocation:
Low Moderate High
CA-5 CA-5 CA-5

Control Description

The organization:

a. Develops a plan of action and milestones for the information system to document the organization's planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system; and

b. Updates existing plan of action and milestones [Assignment: organization-defined frequency] based on the findings from security controls assessments, security impact analyses, and continuous monitoring activities.

Supplemental Guidance

Plans of action and milestones are key documents in security authorization packages and are subject to federal reporting requirements established by OMB.

Related to: CA-2CA-7CM-4PM-4

Control Enhancements

CA-5(1) PLAN OF ACTION AND MILESTONES | AUTOMATION SUPPORT FOR ACCURACY / CURRENCY
The organization employs automated mechanisms to help ensure that the plan of action and milestones for the information system is accurate, up to date, and readily available.