Sample data · read only
Sample POA&M Register
Acme Federal System (Moderate baseline)
This is illustrative sample data for a fictional system. Nothing here can be edited, and no status determinations or dispositions are recorded. Sign in to create a register of your own.
Open items
4
Overdue
4
Due in 30 days
0
Risk-accepted
1
6 of 6 items
| Finding ID | Weakness | Source | Controls | Severity | Scheduled | Status | Δ Days | POC |
|---|---|---|---|---|---|---|---|---|
| AFS-001 | Unpatched CVE-2024-3094 on application server hosting payment intake | Vulnerability Scan | SI-2 | High | 1970-01-31 | OngoingOverdue | 20680d over | J. Reyes, System Owner |
| AFS-006 | Outdated OpenSSH server permitting weak KEX algorithms | Vulnerability Scan | SC-8, CM-6 | High | 1969-12-02 | Completed | 20740d over | J. Reyes, System Owner |
| AFS-002 | Inactive privileged accounts not disabled within 30-day policy threshold | Security Assessment | AC-2 | Moderate | 1970-04-01 | OngoingOverdue | 20620d over | K. Park, IAM Lead |
| AFS-003 | Audit log retention configured below organizational requirement | Security Assessment | AU-11 | Moderate | 1969-12-17 | DelayedOverdue | 20725d over | M. Olsen, SIEM Engineer |
Weakness description AU-11 requires 1-year online retention. Current SIEM index retention set to 90 days. Identified during assessment evidence review.
Milestones
History
| ||||||||
| AFS-005 | Legacy TLS 1.0 endpoint maintained for downstream partner integration | Continuous Monitoring | SC-8, SC-13 | Moderate | 1971-01-01 | Risk-Accepted | 20345d over | R. Khan, ISSM |
| AFS-004 | Missing session inactivity timeout on internal analytics console | Self-Identified | AC-12 | Low | 1970-06-30 | OngoingOverdue | 20530d over | D. Hughes, App Dev Lead |
Ready to track your own findings?
Sign in to create a register, import scan output, draft remediation language, and generate continuous-monitoring status. Status determinations and dispositions stay with the ISSO/ISSM.
Sign in