
Welcome to CyberBytes where we teach you about different Cybersecurity topics in small “bytes”. This week’s topic is Plan of Action & Milestones (POA&M).
Think of a Plan of Action & Milestones as a to-do list for fixing security issues. When risks pop up, a POA&M tracks what’s wrong, how to fix it, and who’s responsible.
But not every risk gets fixed immediately. Some risks are accepted but only by the Authorizing Official (AO), the person who decides if a system gets an ATO (Authority to Operate).
What Risks Get Accepted?
Low impact risks – Not a huge security threat.
Temporary risks – Being actively fixed.
Mission-critical risks – The system is too important to shut down.
A POA&M keeps security on track while ensuring the system can still operate. No POA&M, No ATO.







Leave a comment