Plan of Action and Milestones CA-5
Assessment, Authorization, and Monitoring · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CA-5 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Assessment, Authorization, and Monitoring family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CA-5 (Plan of Action and Milestones) is the to-do list for fixing what the assessment found. A POA&M (Plan of Action and Milestones) is a living document: for each known weakness or vulnerability it records the planned fix, who owns it, and a target date, then tracks it to closure. You update it on a schedule as findings come in from assessments, audits, and continuous monitoring. It is part of the Low baseline — and it is essentially the kind of tracking PlumbTrack is helping you keep.
What good looks like
- List every known weakness — findings from control assessments, audits, and continuous monitoring all land in one place.
- For each item, record the fix: the planned remediation, the owner, and a target milestone date.
- Track to closure — open, in progress, or completed — so nothing quietly lingers.
- Update on a defined frequency as new findings arrive, rather than writing it once and letting it go stale.
- Be honest about risk you are accepting — if an item will not be fixed, say so and say why, instead of leaving it blank.
Framework mapping
- NIST CSF 2.0 — ID.IM-01 — Improvements are identified from evaluations
How to move it toward Implemented
- Build the POA&M from what the host already reports — pull Lynis suggestions,
apt list --upgradablefor pending patches, and any assessment or scan findings into one dated table. - For each row, add the planned fix, an owner, a target date, and a status (open / in progress / completed).
- Set a review cadence (for example, monthly) to re-pull findings and update statuses, so the POA&M stays live.
- Attach the dated POA&M file as hardening evidence on the asset, naming
CA-5in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.