nerdexam
(ISC)2

CGRC · Question #16

Which of the following tasks are identified by the Plan of Action and Milestones document? Each correct answer represents a complete solution. Choose all that apply. Response:

The correct answer is B. The resources needed to accomplish the elements of the plan C. Any milestones that are needed in meeting the tasks D. The tasks that are required to be accomplished E. Scheduled completion dates for the milestones. A Plan of Action and Milestones (POA&M) document is a formal management tool that outlines remediation efforts for identified security weaknesses, including specific tasks, required resources, milestones, and scheduled completion dates.

Compliance Maintenance

Question

Which of the following tasks are identified by the Plan of Action and Milestones document? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • AThe plans that need to be implemented
  • BThe resources needed to accomplish the elements of the plan
  • CAny milestones that are needed in meeting the tasks
  • DThe tasks that are required to be accomplished
  • EScheduled completion dates for the milestones

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    88% (29)

Why each option

A Plan of Action and Milestones (POA&M) document is a formal management tool that outlines remediation efforts for identified security weaknesses, including specific tasks, required resources, milestones, and scheduled completion dates.

AThe plans that need to be implemented

While a POA&M details plans, 'The plans that need to be implemented' is too vague and broad compared to the specific, actionable elements (tasks, resources, milestones, dates) it is required to contain.

BThe resources needed to accomplish the elements of the planCorrect

A POA&M includes the specific resources (e.g., personnel, funding, equipment) required to successfully implement the corrective actions for identified vulnerabilities.

CAny milestones that are needed in meeting the tasksCorrect

Milestones are critical checkpoints within the POA&M that define significant progress points or sub-goals towards completing the overall remediation plan.

DThe tasks that are required to be accomplishedCorrect

The POA&M clearly defines the specific tasks or actions that need to be accomplished to address identified security weaknesses or vulnerabilities.

EScheduled completion dates for the milestonesCorrect

Each milestone and task within a POA&M is assigned a scheduled completion date to ensure accountability and track progress towards remediation and compliance.

Concept tested: Plan of Action and Milestones (POA&M) Components

Source: https://csrc.nist.gov/glossary/term/plan_of_action_and_milestones

Topics

#POA&M#NIST RMF#Compliance Tracking#Remediation Planning

Community Discussion

No community discussion yet for this question.

Full CGRC Practice