Risk: High & above
Showing 1–12 of 96 · sorted by scheduled completion
POA&M ID Weakness Name Controls Source Risk Status Owner Sched. Completion Tasks
POAM-0142 Unsupported OpenSSL version on bastion hosts Remote host contains one or more unsupported versions of OpenSSL. Vendor no longer provides patches. RA-5 SC-13 Vulnerability Scan Critical In Progress
RKR. Kaur
2026-07-14 · 23d late
3/5
POAM-0138 MFA not enforced for privileged console access Break-glass accounts can authenticate to the management console with a password only. IA-2(1) AC-2 3PAO Assessment Critical Pending Review
DMD. Mitchell
2026-07-22 · 15d late
4/4
POAM-0121 Log retention below 12-month baseline in audit store Audit records are rotated at 90 days; the SSP commits to 12 months online retention. AU-11 AU-4 Internal Audit High Delayed
TNT. Nguyen
2026-08-01 · 5d late
1/4
POAM-0155 Default TLS ciphers permitted on public load balancer TLS 1.0/1.1 and CBC cipher suites negotiated successfully against the public endpoint. SC-8 SC-13 Penetration Test High In Progress
MPM. Patel
2026-08-11 · in 5d
2/3
POAM-0147 Apache Struts RCE (CVE-2026-11842) on reporting tier Vendor dependency — fix bundled in ReportWorks 8.4, GA scheduled Q4. SI-2 RA-5 Vulnerability Scan High Open
RKR. Kaur
2026-08-14 · in 8d
1/3
POAM-0163 Quarterly access recertification not evidenced for Q2 Reviews were performed but attestation records were not retained in the evidence repository. AC-2(j) PS-4 Customer Audit Moderate In Progress
JBJ. Brooks
2026-08-19 · in 13d
2/4
POAM-0170 Backup restoration test not performed in period CP-9 requires a documented restoration test each six months; last evidence dated 2025-11. CP-9 CP-10 Internal Audit Moderate Open
TNT. Nguyen
2026-08-28 · in 22d
0/3
POAM-0181 Session timeout exceeds 15 minutes on admin portal Idle session terminates after 60 minutes; baseline requires 15. AC-11 Manual Observation Moderate Draft Unassigned 2026-09-04 · in 29d No tasks
POAM-0188 Missing security headers on tenant web application CSP, HSTS and X-Frame-Options absent on three tenant-facing routes. SC-7 SI-10 Penetration Test Low Open
MPM. Patel
2026-11-30 · in 116d
1/2
POAM-0190 Informational: TLS certificate expires within 60 days Operational requirement approved — renewal handled by the managed certificate pipeline. SC-12 Vulnerability Scan Low Operational Req.
TNT. Nguyen
2026-12-15 · in 131d Not applicable
10 of 96 items

218 closed POA&M items

Items move here when all corrective actions are applied and evidence of remediation has been verified, or when a false-positive deviation is approved.

31 configuration findings

Benchmark deviations tracked on their own worksheet in the FedRAMP template, with identical columns to the open items tab.

7 deviation requests awaiting AO decision

Risk adjustments, false positives and operational requirements. Approved risk adjustments and operational requirements stay on the open tab as tracked risks.