Skip to content
ControlVerdict
CA.L2-3.12.2addresses
CA.L2-3.12.2Operational Plan of Action
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
  • [a]

    deficiencies and vulnerabilities to be addressed by the plan of action are identified;
  • [b]

    a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities; and
  • [c]

    the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.

View full control

Every POA&M item carries an owner, a funding line, and a closure test

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses all Operational Plan of Action objectives: identifying the deficiencies and vulnerabilities to address, developing the plan, and implementing it.

Identifying deficiencies. Four intake channels feed one register: control assessment findings, vulnerability scan results that cannot be patched inside the SLA, incident after-action items, and external audit or customer findings. Each item records the source, the practice or objective affected, and the risk if left open. Duplicates are merged so a single root cause does not appear as five items.

Developing the plan. An item is not accepted into the register without: a named accountable owner (a person, not a department), the corrective action described concretely enough to test, a resource estimate, a scheduled completion date, and any interim compensating control. Items needing capital carry a budget line reference; that is why the CFO attends the review, and it is why dates in this register tend to hold.

Implementing. Corrective actions execute through normal change management with the ticket linked to the register item, so the work leaves the same audit trail as any other change. Milestones are updated monthly; a slipped date requires a written reason and a new date approved by the ISSO, and slipping twice escalates to the executive sponsor.

Closure. An item closes only after a closure test performed by someone other than the implementer, with the test result attached. Closure without evidence is not permitted by the workflow.

Maintenance. Monthly review of all open items; quarterly trend report on aging and on how many items were found internally versus externally. Long-lived items are re-risk-rated rather than left to drift.

Accepted gap. One legacy manufacturing execution system cannot be brought to the endpoint baseline until it is replaced, which is a multi-year capital project. It remains an open register item with network isolation and enhanced logging as the documented compensating control, re-approved by leadership annually.

What the evidence looks like

  • POA&M register export showing source, owner, milestone, and status for open items
  • Two closed items with the independent closure test attached
  • Change ticket linked to a corrective action
  • Monthly review minutes including the funding decisions
  • Compensating control approval for the long-lived legacy item

Environment

Aerospace subcontractor, ~500 staff. Deficiencies arrive from self-assessment, vulnerability scanning, incidents, and customer audits; the ISSO reviews the register monthly with the CFO because most fixes need money.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.