Implements a process for ensuring that plans of action and milestones for the security program and associated organizational information systems:
Are developed and maintained;
Document the remedial information security actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation; and
Are reported in accordance with OMB FISMA reporting requirements.
Reviews plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.