workflow

Security Control Assessment & POA&M Remediation

Run this assessment on the EXISTING Audit item for the engagement (audit_type: it_audit or compliance) — enrich that record, never create a duplicate: Audit.scope carries the authorization boundary and Audit.period_start/period_end the assessment window. Consumes, from the upstream SSP-development / system-categorization effort, the approved System Security Plan (SSP), the FIPS 199 system categorization, and the tailored NIST 800-53 baseline (existing Control items, framework: nist-800-53). Assess each in-scope control with 800-53A examine/interview/test methods, record satisfied / other-than-satisfied determinations, open a POA&M Issue for every gap, re-validate remediation, and issue the Security Assessment Report (SAR). In scope: control assessment, determinations, the POA&M lifecycle, and the SAR for the authorization boundary agreed at kickoff. Out of scope: the authorization (ATO) decision itself and the steady-state continuous-monitoring cadence. On completion, the frozen SAR and POA&M package are handed to the NIST RMF System Authorization (ATO) Cycle.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
assure

Details

teams
  • it
  • compliance-legal
domains
  • controls
standards
  • nist-800-53
sourceTemplateId
workflow-library:controls-security-assessment-poam-remediation
releaseId
sha256:513af45d886c143c166f32c84f2080655a9a78f1376bd2613ac47d412d1bb6c8
canonicalUrl
https://workflow-library.com/all/?w=controls-security-assessment-poam-remediation
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-AUDIT-21
    • UC-GOV-22
    • UC-RISK-14
    • UC-AUDIT-17
    • UC-ACCESS-05
    • UC-ACCESS-10
    • UC-ACCESS-11
    • UC-ACCESS-12
    • UC-ACCESS-13
    • UC-ACCESS-14
    • UC-ACCESS-16
    • UC-ACCESS-19
    • UC-ASSET-01
    • UC-ASSET-04
    • UC-BCDR-04
    • UC-BCDR-11
    • UC-BCDR-13
    • UC-CONFIG-01
    • UC-CONFIG-03
    • UC-CONFIG-05
    • UC-CONFIG-06
    • UC-CONFIG-07
    • UC-CONFIG-08
    • UC-CONFIG-09
    • UC-CONFIG-10
    • UC-CRYPTO-01
    • UC-CRYPTO-04
    • UC-DATA-11
    • UC-GOV-09
    • UC-GOV-19
    • UC-GOV-25
    • UC-GOV-29
    • UC-GOV-30
    • UC-GOV-31
    • UC-GOV-32
    • UC-GOV-34
    • UC-GOV-35
    • UC-GOV-36
    • UC-HR-01
    • UC-HR-02
    • UC-HR-04
    • UC-IR-02
    • UC-LOG-01
    • UC-LOG-02
    • UC-LOG-03
    • UC-LOG-05
    • UC-LOG-07
    • UC-LOG-08
    • UC-LOG-10
    • UC-LOG-11
    • UC-NET-01
    • UC-NET-02
    • UC-NET-03
    • UC-NET-04
    • UC-NET-05
    • UC-NET-06
    • UC-NET-07
    • UC-NET-08
    • UC-NET-09
    • UC-NET-10
    • UC-NET-11
    • UC-NET-12
    • UC-NET-13
    • UC-NET-14
    • UC-PHYS-01
    • UC-PHYS-02
    • UC-PHYS-03
    • UC-PHYS-04
    • UC-PHYS-05
    • UC-PHYS-06
    • UC-PHYS-07
    • UC-PHYS-08
    • UC-PHYS-09
    • UC-PHYS-10
    • UC-PHYS-11
    • UC-SDLC-11
    • UC-TPRM-07
    • UC-TPRM-09
    • UC-VULN-04
    • UC-VULN-05
    • UC-VULN-06
    • UC-VULN-07
    • UC-VULN-08
    • UC-VULN-09
    • UC-VULN-11
    • UC-ACCESS-06
    • UC-ACCESS-18
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:513af45d886c143c166f32c84f2080655a9a78f1376bd2613ac47d412d1bb6c8

            Connections