NIST SP 800-53 Rev 5 LOW
CA Assessment, Authorization, and Monitoring

NIST SP 800-53 Rev 5 LOW CA-5: Plan of Action and Milestones

Develop POAM; update at least monthly (FedRAMP); track remediation timelines (HIGH 30 days, MOD 90).

What else in your programme already covers this

This control maps to 47 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

CIS Controls v8 · 3 controls

  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.7 Remediate Detected Vulnerabilities

ISO/IEC 42001:2023 · 3 controls

  • 10.2 Nonconformity and corrective action
  • 6.1.3 Risk treatment
  • 8.3 AI risk treatment

APRA CPS 234 · 2 controls

  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • AUCDR-IS-4 Formal vulnerability management program
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

C5 (Germany) · 2 controls

  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • C5-SP-03 Exceptions from Existing Policies and Instructions

DORA · 2 controls

ISO 22301:2019 · 2 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

CMMC 2.0 · 1 control

GDPR · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

ISO 27002:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

ISO 27701:2019 · 1 control

  • 5.6.3 Information security risk treatment

NIS2 Directive · 1 control

  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-218 · 1 control

  • 53A-3.4 Analyze Assessment Report Results

PCI DSS 4.0 · 1 control

  • 11.4.4 Pen test findings remediated

SOC 2 · 1 control

  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CA Assessment, Authorization, and Monitoring

Query this from an agent

The graph holds this control, the 47 it maps to, and the evidence behind each claim, over MCP and REST.