PlumbTrackLive demoGRC Risk System

← control library

Plan of Action and Milestones CA-5

Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds CA-5 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

CA-5 (Plan of Action and Milestones) is the to-do list for fixing what the assessment found. A POA&M (Plan of Action and Milestones) is a living document: for each known weakness or vulnerability it records the planned fix, who owns it, and a target date, then tracks it to closure. You update it on a schedule as findings come in from assessments, audits, and continuous monitoring. It is part of the Low baseline — and it is essentially the kind of tracking PlumbTrack is helping you keep.

What good looks like

Framework mapping

How to move it toward Implemented