Overview
A Plan of Action and Milestones (POA&M) is a critical document used to identify, assess, prioritize, and monitor the progress of corrective efforts for security weaknesses found in programs and systems. While Hyperproof does not currently have a dedicated POA&M module, you can effectively manage these requirements using the Issues or Risk Register modules.
By leveraging custom fields and export capabilities, you can maintain compliance with frameworks like FedRAMP or CMMC while keeping your data centralized.
โ
Key benefits
Centralized tracking: Keep all deficiency remediation efforts within your primary compliance platform.
Seamless reporting: Use CSV and Excel exports to quickly populate official agency templates.
Flexible workflows: Choose the module that best fits your team's existing risk or issue management style.
Using Hyperproof for POA&Ms
Depending on your organization's needs, you can use one of the following three workflows to manage your POA&Ms.
Option 1: The Issues module
This is the most common approach for Hyperproof customers.
Navigate to the Issues module.
Create an issue for each identified deficiency.
Use the Excel export feature to pull your data.
Populate your official POA&M template using the exported data.
Option 2: The Risk Register module
Some customers prefer this method because POA&Ms often sit between risks and issues.
Navigate to the Risk Register.
Manage your POA&Ms within this module to take advantage of a more "Excel-like" management interface.
Option 3: Custom fields and CSV export
For more granular control, you can add specific metadata to your records.
Add POA&M-specific custom fields to your issues.
Fill out the required details for each item.
Select CSV export to download your list.
Copy the data into your official template, such as a FedRAMP or CMMC template.
Best practices
Note: Always use the full name of a feature, like Risk Register, instead of shorthand to help others understand the context.
Use consistent terminology: When creating custom fields, ensure they match the language used in your specific compliance framework.
Keep descriptions concise: Write short, clear descriptions for each deficiency to make them easier to scan.
Turn on notifications: Toggle on alerts for due dates to ensure milestones are met on time.
