POA&M · 5 min read
Writing a POA&M That Holds Up
A weakness that isn't on the POA&M is invisible. Here's how to write entries an assessor will accept.
What a POA&M is for
A Plan of Action and Milestones is the authoritative, living record of every known weakness in a system and the plan to fix it. It is the spine of continuous monitoring: assessment findings, scan results, and pen-test findings all flow into it. The governing principle is simple: a weakness that is not on the POA&M is invisible to the risk picture, so everything gets logged.
Anatomy of a strong entry
Every defensible POA&M item names, at minimum:
- The weakness: what is wrong, factually and specifically (not 'security needs improvement').
- The related control: the 800-53 control (or requirement) the weakness maps to.
- The owner: a named, accountable person or role.
- Milestones: the concrete steps to remediation.
- An estimated completion date (ECD): a realistic date, not 'TBD'.
- Resources required and status (open / ongoing / completed).
Traceability is everything
An assessor will pick a finding from the SAR or a scan and ask, *'show me this on the POA&M.'* Each entry should trace back to the finding that created it. When a pen-test finding (often a REM number) maps cleanly to a POA&M item with an ECD, you demonstrate that the risk is *managed*, not just *known*.
Common mistakes
- Vague weaknesses that can't be tested as closed.
- ECDs that quietly slip with no updated milestone or justification.
- Findings that live in an email thread but never make it onto the POA&M.
- Closing an item without evidence that the weakness is actually remediated.
Keep it current on the monthly ConMon cadence and the POA&M becomes your strongest evidence that the program is alive.
