CCI-000142
CCI-000142 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - a process to ensure that plans of action and milestones for the information security program and associated Organizational systems are developed. - a process to ensure that plans of action and milestones for the information security program and associated Organizational systems are maintained. - a process to ensure that plans of action and milestones for the privacy program and associated Organizational systems are developed. - a process to ensure that plans of action and milestones for the privacy program and associated Organizational systems are maintained. - a process to ensure that plans of action and milestones for the supply chain risk management program and associated Organizational systems are developed. - a process to ensure that plans of action and milestones for the supply chain risk management program and associated Organizational systems are maintained.
Validation Procedures
Examine: [SELECT FROM: Information security program plan; plans of action and milestones; procedures addressing plans of action and milestones development and maintenance; procedures addressing plans of action and milestones reporting; procedures for reviewing plans of action and milestones for consistency with risk management strategy and risk response priorities; results of risk assessments associated with plans of action and milestones; OMB FISMA reporting requirements; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with responsibilities for developing, maintaining, reviewing, and reporting plans of action and milestones; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Organizational processes for plan of action and milestones development, review, maintenance, and reporting; mechanisms supporting plans of action and milestones].