All of the false positives, found during the annual assessment, should be added to the plan of action and milestones (POA&M). If they are approved before the SAR is closed/signed, they are moved to the “Closed POA&M Items” tab. If they have not been approved, they should remain in the “Open POA&M Items” tab until approved. Then, at least annually during assessment, the false positives should be evaluated for continued false positive status. For more information on handling the annual assessment and scan findings review the FedRAMP Continuous Monitoring Strategy Guide [PDF - 1.11MB].
Comments
0 comments
Please sign in to leave a comment.