POAM

From MgmtWiki
Revision as of 22:28, 18 January 2022 by Tom (talk | contribs) (Problems)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Full Title

Plan of Action and Milestones

Context

  • NIST defined the term from several of their special publications and it is widely adopted across the US Federal Government for showing compliance.

Problems

  • This appears indistinguishable from a bug list in program development.
  • Most government forms and codes are unknown outside of the government of interest. There are many consultants (aka beltway bandits) will be happy to take your money to fill out forms that the government claims are simplicity itself.

Solution

Just names, whatever.

  • A POAM NIST template is included in several DFARS template packages. CKSS has compiled a suite of DFARS 252.204-7012 compliance templates to help DOD contractors get a jumpstart on their remediation activities as well as ensure continued compliance.

References