3.11.4

  • Requirement

    Respond to findings from security assessments, monitoring, and audits.

  • Discussion

    This requirement addresses the need to determine an appropriate response to risk before generating a plan of action and milestones (POAM) entry. It may be possible to mitigate the risk immediately so that a POAM entry is not needed. However, a POAM entry is generated if the risk response is to mitigate the identified risk and the mitigation cannot be completed immediately.

More Info

  • Family

    Risk Assessment
  • Related NIST 800-53 ID

    RA-07
  • Reference Documents

    • N/A

NIST 800-171A r3 Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!