The POA&M, and SSP
Maintaining a Plan of Action & Milestones (POA&M) and System Security Plan (SSP) is fundamental to all Federal Systems guidance. NIST 171 and CMMC require the POA&M, Plan of Action and Milestones, a document for a system that identifies tasks needing to be accomplished. Only recently associated with the DoD Assessment, the POA&M details resources required to achieve the plan’s elements, any milestones in meeting the tasks, and scheduled completion dates for the milestones. [xxxi]
Exclusive to Levels 2 and 3 of the CMMC, DoD, and the Office of the Under Secretary of Defense Acquisitions and Sustainment intend to allow companies to receive contract awards providing they have a Plan of Actions and Milestones (POA&M) in place, and it lists targets to complete any outstanding CMMC requirements. The Department intends to specify a baseline number of requirements that must be achieved before contract award and allow a remaining subset to be addressed in a POA&M within a clearly defined timeline. The Department also intends to specify a small subset of requirements that cannot be on a POA&M to achieve a CMMC certification. To learn more about the format and purpose of a POA&M, refer to the following guidelines and templates Integrating Cybersecurity and Enterprise Risk Management (ERM) (nist.gov) and CSP POAM Template Completion Guide (fedramp.gov). If designing an automated POA&M, use the NIST OSCAL Assessment Layer: Plan of Action and Milestones Model located at Plan of Action and Milestones Model (nist.gov).
The POA&M, as a control activity, is among the Derived security requirements. Whether the assessor is assigned internally to the organization or as a third party, the following elements are required to NIST SP 800-171 3.12.2, which is necessary to submit the assessment. This ongoing activity is part of a CUI program, and the POA&M is always required. (See Figure 10 Requirements for Scoring Guidance)
|
3.12.2 |
SECURITY REQUIREMENT Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. |
|
|
|
ASSESSMENT OBJECTIVE Determine if: |
|
|
3.12.2[a] |
deficiencies and vulnerabilities to be addressed by the plan of action are identified. |
|
|
3.12.2[b] |
a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. |
|
|
3.12.2[c] |
the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. |
|
|
POTENTIAL ASSESSMENT METHODS AND OBJECTS Examine: [SELECT FROM: Security assessment and authorization policy; procedures addressing plan of action; system security plan; security assessment plan; security assessment report; security assessment evidence; plan of action; other relevant documents or records]. Interview: [SELECT FROM: Personnel with a plan of action development and implementation responsibilities; personnel with information security responsibilities]. Test: [SELECT FROM: Mechanisms for developing, implementing, and maintaining a plan of action]. |
||
Table 5 NIST 171A Assessment method for 3.12.2 POA&M requirement
The System Security Plan (SSP) is a part of the Derived Requirements, NIST 171 3.12.4, and it is a core component necessary to all forms of assessment from Low to High. As both a sample control and an evaluation of whether the SSP is satisfactory as an element of the Assessment program itself, consider the flow of [a] through [h] in determining if the Vendor has satisfied the control. The evidence collected would include the completed plan. That plan would be given consideration relative to the associated POA&M, showing adherence to the policies and procedures necessary to maintain adequate security.
|
3.12.4 |
SECURITY REQUIREMENT Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. |
|
|
|
ASSESSMENT OBJECTIVE Determine if: |
|
|
3.12.4[a] |
a system security plan is developed. |
|
|
3.12.4[b] |
the system boundary is described and documented in the system security plan. |
|
|
3.12.4[c] |
the system environment of operation is described and documented in the system security plan. |
|
|
3.12.4[d] |
the security requirements identified and approved by the designated authority as non-applicable are identified. |
|
|
3.12.4[e] |
the method of security requirement implementation is described and documented in the system security plan. |
|
|
3.12.4[f] |
the relationship with or connection to other systems is described and documented in the system security plan. |
|
|
3.12.4[g] |
the frequency to update the system security plan is defined. |
|
|
3.12.4[h] |
system security plan is updated with the defined frequency. |
|
|
POTENTIAL ASSESSMENT METHODS AND OBJECTS Examine: [SELECT FROM: Security planning policy; procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; other relevant documents or records]. Interview: [SELECT FROM: Personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities]. Test: [SELECT FROM: Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan]. |
||
Table 6 - Sample Assessment Method for Security Requirement 3.12.4 System Security Plans
As explained by SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Systems[xxxii] “The objective of system security planning is to improve the protection of information system resources. [...] The protection of a system must be documented in a system security plan. The completion of system security plans is a requirement of the Office of Management and Budget (OMB) Circular A-130, "Management of Federal Information Resources," Appendix III, "Security of Federal Automated Information Resources," and Title III of the E-Government Act, entitled the Federal Information Security Management Act (FISMA), The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates the responsibilities and expected behavior of all individuals who access the system. The system security plan should be viewed as documentation of the structured planning process adequate, cost-effective security protection for a system. It should reflect input from various managers with responsibilities concerning the system, including information owners, the system owner, and the senior agency information security officer (SAISO). Additional information may be included in the basic plan and the structure and format organized according to agency needs, so long as the major sections described in this document are adequately covered and readily identifiable.
There are numerous resources to assist in creating the SSP, including the template provided within NIST SP800-18, Guide for Developing Security Plans for Federal Information Systems. [xxxii] One recent resource is the System Security Plan How to for CMMC and NIST SP 800-171 DoD self-assessment training video offered by CMMCaudit.org. [xxxiii]

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics