You may toil with a consultant for hours over your System Security Plan. You have probably marked a dozen snakeoil emails as spam after they promised to get plans in place in hours or minutes. But have you ever used your SSP as the document to guide your CUI protection? Have you created a plan that actually helps you get stuff done?

Your plan, for your business, must assist you in planning to do your business, or you have no plan at all. Stop thinking of your Plan of Action & Milestones as a required CMMC compliance document.

Plans take steps to get stuff done. Your POAM describes the steps and sets key milestones to getting that stuff done. It should list who will get that stuff done, and when they will complete the steps to do the stuff.

You do not have to wait until you have a System in place for NIST-800-171 to handle Controlled Unclassified Information. Once you know will engineer a system to protect the confidentiality of CUI start a POAM. Make a punch list. Get it done.

Plan of Action And Milestones

The POAM comes out of NIST-SP-800-53, which NIST designed for federal systems. This means guidance, and AI created templates may not fit the unique needs of your business.

Just think of the POAM as your punch list for getting things done. Directly from NIST-SP-800-53 we get a definition o the Plan of Action and Milestone as:

Control: a. Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system; and

b. Update existing plan of action and milestones [Assignment: organization-defined frequency]based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.

People may read the first bullet point and think, “Gee the POAM comes after the assessment,” but if you look to the second half you update your existing Plan. Meaning it existed before the assessment

Meaning a POAM does not pop out as some bastard child of a a Gap Analysis, you create a Plan of Action and Milestone when you begin to engineer a system to protect the confidentiality of CUI. That system came into existence when you accepted 7012 flow downs.

Make your list, start getting stuff done. In related controls of -53 NIST goes on to define the POAM process:

PLAN OF ACTION AND MILESTONES PROCESS

Control:

a. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems:

  1. Are developed and maintained;

  2. Document the remedial information security, privacy, and supply chain risk management actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation; and

  3. Are reported in accordance with established reporting requirements.

b. Review plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

That sounds like a lot for a small business. Remember, NIST wrote 53 for federal systems. In 171 revision three we find:

03.12.02 Plan of Action and Milestones a. Develop a plan of action and milestones for the system:

  1. To document the planned remediation actions to correct weaknesses or deficiencies noted during security assessments and
  2. To reduce or eliminate known system vulnerabilities.

b. Update the existing plan of action and milestones based on the findings from:

  1. Security assessments,
  2. Audits or reviews, and
  3. Continuous monitoring activities.

The important commonality? You make a risk based decision based on your businesses. So many companies try to get a CUI enclave built and they don’t have basic back ups and MFA solved across the commercial enterprise. Those companies, unless facing pressure on a contract or from a Prime, have set the wrong milestones based on risks.

CMMC does not serve as your cybersecurity plan. NIST-SP-800-171 does not give you a cybersecurity framework. You nest how you meet the requirements within your larger security plan. That does not mean you can’t use CMMC and 171 to get better at the basics. If you create a punchlist based on risks, you by nature of thise risks knock out the basics, first, on your way to meeting 320 objectives.

ten step POAM

Now let’s say you used this for your punch list to towards CMMC compliance. Would your Plan of Actions and Milestones move you toward the goal?

Item POA&M Action Primary NIST SP 800-171 Rev. 2 Requirement Related Requirements Compliance Considerations
1 Inventory hardware, software, firmware, and other system components. 3.4.1 — Establish and maintain baseline configurations and inventories of organizational systems. The inventory should include hardware, software, firmware, and relevant documentation within the CUI system boundary.
2 Establish a method for tracking system changes. 3.4.3 — Track, review, approve or disapprove, and log changes to organizational systems. 3.4.4, 3.4.5 A spreadsheet may be sufficient if it records the requested change, security-impact analysis, approval, implementation, testing, and closure.
3 Document where CUI enters, moves through, and leaves the organization. 3.12.4 — Develop, document, and periodically update the System Security Plan. 3.1.3, 3.13.1, 3.13.2 Business-flow, data-flow, and network diagrams should identify the CUI boundary, external connections, internal connections, users, systems, and service providers.
4 Implement and test multifactor authentication. 3.5.3 — Use multifactor authentication for privileged and nonprivileged accounts when required. 3.5.1, 3.5.2 Rev. 2 requires MFA for local and network access to privileged accounts and network access to nonprivileged accounts. Testing should cover every applicable access path.
5 Remove, replace, or protect unsupported and end-of-life systems. 3.14.1 — Identify, report, and correct system flaws in a timely manner. 3.11.3, 3.4.6, 3.4.7 Unsupported products should be upgraded, replaced, removed, isolated, or addressed through documented alternative safeguards.
6 Back up information and test restoration procedures. 3.8.9 — Protect the confidentiality of backup CUI at storage locations. Rev. 2 does not contain a general backup or restoration-testing requirement. Requirement 3.8.9 applies when backups contain CUI and focuses on protecting their confidentiality.
7 Conduct vulnerability scanning and review the results. 3.11.2 — Scan for vulnerabilities periodically and when new vulnerabilities are identified. 3.11.3 Scanning addresses 3.11.2. Findings must also be prioritized, tracked, and remediated under 3.11.3.
8 Establish a controlled enclave for processing, storing, and transmitting CUI. 3.12.4 — Document the system boundary and security requirement implementation. 3.1.3, 3.13.1, 3.13.2 NIST SP 800-171 does not specifically require a CUI enclave. An enclave is an architectural approach that can reduce scope and support multiple security requirements.
9 Restrict and test access to the CUI enclave. 3.1.1 — Limit system access to authorized users, processes, and devices. 3.1.2, 3.1.3, 3.5.1, 3.5.2, 3.12.1, 3.13.1 Testing should verify authorized users, approved devices, permitted functions, authentication, information-flow restrictions, and boundary protections.
10 Establish rules governing AI use and information sharing. 3.1.3 — Control the flow of CUI in accordance with approved authorizations. 3.1.20, 3.1.22, 3.2.1, 3.2.2 Rev. 2 contains no AI-specific requirement. Policies should prohibit entering CUI into unapproved AI services and should be supported by training, access restrictions, and technical controls.

As a small business owner, which Plan of Action will serve you better as a punchlist? You might make more headway with a simplified POAM, like the one in the image, and by the time you complete you would understand the mappings to NIST-SP-800-171 in the second table.

Don’t wait on the POAM. Make your punch list today and do the work. How you get stuff done.

Overtime your POAM will evolve, and it will look more formalized following your Gap Analysis, but never forget the “action” in POAM. The tool lives in situ, not as an artifact. And don’t forget the word Plan in both SSP and POAM. If you don’t find these documents useful to getting stuff done do you really have a plan at all?

Start small and iterate.