CMMC 1.0 Practice CA.2.159 Requirement:
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
CMMC 1.0 CA.2.159 Requirement Explanation:
Plans of action address how and when you plan to implement any absent CMMC practices and processes. You need to complete the items on your POA&M before attempting a formal CMMC assessment.
Example CMMC 1.0 CA.2.159 Implementation:
Create a plan of action and milestones (POA&M) document to list any unimplemented security requirements identified in security assessments. Your POA&M should include who is responsible for each item, specific steps necessary to implement the item, milestones to measure progress, and completion dates.
CMMC 1.0 CA.2.159 Scenario(s):
- Scenario 1:
Your company has under gone a security assessment/gap analysis in which it was determined that 10 security practices were not implemented. These practices were added to your POA&M and assigned responsible persons and completion dates.
Discover Our NIST SP 800-171 & CMMC 2.0 Solutions:
Power through compliance. Meet and maintain your NIST SP 800-171 & CMMC 2.0 compliance requirements.
Transform your business. Create new revenue streams and provide scalability for your NIST SP 800-171 and CMMC 2.0 services.
Supply Chain Verifier
Trust is everything. Verify, monitor, and support subcontactor compliance.