NIST 800-171 Controls · Security Assessment
CA.2.002 — Develop and Implement Plans of Action
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
What CA.2.002 means in plain English
When you find a security gap — from your self-assessment, a vulnerability scan, or an incident — you need to write it down in a formal Plan of Action and Milestones (POA&M). This is basically a to-do list for security fixes with deadlines. For each gap, record what the problem is, how you plan to fix it, who is responsible, and when it will be done. The DoD takes POA&Ms seriously — you will submit your SPRS score alongside any open POA&M items.
The assessment question
“Do you maintain a Plan of Action and Milestones (POA&M) that documents all known security deficiencies with planned corrective actions, responsible parties, and target completion dates?”
How to implement CA.2.002
- Create a POA&M spreadsheet with columns: ID, Control Reference, Weakness Description, Severity, Planned Corrective Action, Responsible Person, Resources Required, Start Date, Target Completion Date, Milestones, and Status.
- Populate the POA&M with all known gaps from your self-assessment, vulnerability scans, and any audit findings. Do not leave anything out — an honest POA&M is better than a hidden gap.
- Set realistic target dates: critical items within 30 days, high within 90 days, medium within 180 days. Assign a specific person (not a department) to each item.
- Review the POA&M at least monthly: update status on each item, close completed items with evidence, and add any new items discovered.
- Store the POA&M alongside your SSP and be prepared to submit it to your prime contractor or the DoD if requested.
Evidence your assessor will ask for
- Current POA&M document with all open security deficiencies
- Evidence of regular POA&M reviews (monthly review meeting notes or update timestamps)
- Closed POA&M items with evidence of completed remediation
- POA&M tied to self-assessment findings and vulnerability scan results
- Responsible parties assigned to each POA&M item
Does AI prompt monitoring help with this control? Honestly, no.
CA.2.002 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Security Assessment controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.