| POA&M ID ▲ | Weakness Name | Controls | Source | Risk ▼ | Status | Owner | Sched. Completion | Tasks | ||
|---|---|---|---|---|---|---|---|---|---|---|
| POAM-0142 | Unsupported OpenSSL version on bastion hosts Remote host contains one or more unsupported versions of OpenSSL. Vendor no longer provides patches. | RA-5 SC-13 | Vulnerability Scan | Critical | In Progress | RKR. Kaur |
2026-07-14 · 23d late |
3/5 |
||
| POAM-0138 | MFA not enforced for privileged console access Break-glass accounts can authenticate to the management console with a password only. | IA-2(1) AC-2 | 3PAO Assessment | Critical | Pending Review | DMD. Mitchell |
2026-07-22 · 15d late | 4/4 |
||
| POAM-0121 | Log retention below 12-month baseline in audit store Audit records are rotated at 90 days; the SSP commits to 12 months online retention. | AU-11 AU-4 | Internal Audit | High | Delayed | TNT. Nguyen |
2026-08-01 · 5d late | 1/4 |
||
| POAM-0155 | Default TLS ciphers permitted on public load balancer TLS 1.0/1.1 and CBC cipher suites negotiated successfully against the public endpoint. | SC-8 SC-13 | Penetration Test | High | In Progress | MPM. Patel |
2026-08-11 · in 5d | 2/3 |
||
| POAM-0147 | Apache Struts RCE (CVE-2026-11842) on reporting tier Vendor dependency — fix bundled in ReportWorks 8.4, GA scheduled Q4. | SI-2 RA-5 | Vulnerability Scan | High | Open | RKR. Kaur |
2026-08-14 · in 8d | 1/3 |
||
| POAM-0163 | Quarterly access recertification not evidenced for Q2 Reviews were performed but attestation records were not retained in the evidence repository. | AC-2(j) PS-4 | Customer Audit | Moderate | In Progress | JBJ. Brooks |
2026-08-19 · in 13d | 2/4 |
||
| POAM-0170 | Backup restoration test not performed in period CP-9 requires a documented restoration test each six months; last evidence dated 2025-11. | CP-9 CP-10 | Internal Audit | Moderate | Open | TNT. Nguyen |
2026-08-28 · in 22d | 0/3 |
||
| POAM-0181 | Session timeout exceeds 15 minutes on admin portal Idle session terminates after 60 minutes; baseline requires 15. | AC-11 | Manual Observation | Moderate | Draft | Unassigned | 2026-09-04 · in 29d | No tasks | ||
| POAM-0188 | Missing security headers on tenant web application CSP, HSTS and X-Frame-Options absent on three tenant-facing routes. | SC-7 SI-10 | Penetration Test | Low | Open | MPM. Patel |
2026-11-30 · in 116d | 1/2 |
||
| POAM-0190 | Informational: TLS certificate expires within 60 days Operational requirement approved — renewal handled by the managed certificate pipeline. | SC-12 | Vulnerability Scan | Low | Operational Req. | TNT. Nguyen |
2026-12-15 · in 131d | Not applicable |
Items move here when all corrective actions are applied and evidence of remediation has been verified, or when a false-positive deviation is approved.
Benchmark deviations tracked on their own worksheet in the FedRAMP template, with identical columns to the open items tab.
Risk adjustments, false positives and operational requirements. Approved risk adjustments and operational requirements stay on the open tab as tracked risks.