PM-4 Plan of Action and Milestones Processes
Statement
The University shall develop and update, a plan of action and milestone process for security information resources that document the University’s planned, implemented, and evaluated remedial actions to correct deficiencies noted during the assessment of the security controls to reduce or eliminate known vulnerabilities in the system.
Applicability
This Control applies to all West Texas A&M network information resources. The responsibility and authority for this control is delegated to the ISO.
Implementation
The ISO shall develop a plan of action and milestone process for the information system that documents the organization’s planned, implemented, and evaluated remedial actions to correct deficiencies noted during the assessment of the security controls to reduce or eliminate known vulnerabilities in the system. The plan shall be reviewed periodically for consistency and changes in organizational priorities.