6 items breach their FedRAMP remediation window.
High and critical risk findings must be remediated within 30 days of discovery; moderate within 90 days; low within 180 days.
Open POA&M Items
96
across 4 systems
Due in Next 30 Days
23
8 assigned to you
Evidence Awaiting Review
9
oldest waiting 6 days
Open POA&M Items by Risk Rating
Adjusted rating where a deviation was approved
Table view
Workflow Pipeline
Where the 96 open items sit right now
Table view
POA&M Items Opened vs. Closed
Rolling 8 months · Jan – Aug 2026
Past Due & Due Within 30 Days
Ordered by scheduled completion date
POA&M ID
Weakness
Risk
Owner
Scheduled Completion
POAM-0142
Unsupported OpenSSL version on bastion hosts
RA-5, SC-13 · Tenable plugin 19506
Critical
RK R. Kaur
2026-07-14 · 23d late
POAM-0138
MFA not enforced for privileged console access
IA-2(1), AC-2 · 3PAO assessment finding
Critical
DM D. Mitchell
2026-07-22 · 15d late
POAM-0121
Log retention below 12-month baseline in audit store
AU-11, AU-4 · Internal audit
High
TN T. Nguyen
2026-08-01 · 5d late
POAM-0155
Default TLS ciphers permitted on public load balancer
SC-8, SC-13 · Penetration test
High
MP M. Patel
2026-08-11 · in 5d
POAM-0163
Quarterly access recertification not evidenced for Q2
AC-2(j), PS-4 · Customer audit
Moderate
JB J. Brooks
2026-08-19 · in 13d
POAM-0170
Backup restoration test not performed in period
CP-9, CP-10 · Internal audit
Moderate
TN T. Nguyen
2026-08-28 · in 22d
M. Patel closed
POAM-0119 — evidence verified
Today, 09:41 AM
T. Nguyen uploaded
patch-report-aug.pdf to
POAM-0142
Today, 08:56 AM
D. Mitchell changed status on
POAM-0138
In Progress → Pending Review
Yesterday, 04:30 PM
System flagged
POAM-0121 as past due
Yesterday, 12:00 AM
R. Kaur commented on
POAM-0142
Aug 4, 03:18 PM
J. Brooks created 12 POA&M items from a FedRAMP import
Aug 3, 10:05 AM
Findings by Detection Source
All 148 findings, framework-agnostic
Table view
Remediation Window Compliance
Critical/High 30d · Moderate 90d · Low 180d
Table view