1Overview
CA.L2-3.12.2 is the plan-of-action requirement, the control that governs how deficiencies are corrected. It requires that the organization develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in its systems, so that known gaps have a documented path to closure and are actually closed. It is a three-point requirement that cannot be deferred on a plan of action.
Assessments and scans reveal deficiencies, and a plan of action, the POA&M, is the structured way to correct them: it identifies what needs fixing, sets out how and when it will be fixed, and is then carried through. This control requires both developing those plans, so deficiencies are documented with a path to resolution, and implementing them, so the corrections actually happen. It is the mechanism by which a program moves from knowing about a gap to closing it. There is a fitting note here: this control, about plans of action, is itself one that cannot be placed on a plan of action.
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
The requirement has three parts the assessment objectives make explicit: the deficiencies and vulnerabilities to be addressed are identified, a plan of action is developed to correct them, and the plan is implemented. Identification defines what the plan covers; development produces the documented plan with corrective actions; implementation carries those actions out. Together they ensure deficiencies are not merely recorded but resolved.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.12.2 into three objectives: identify the deficiencies, develop the plan, and implement it.
Deficiencies and vulnerabilities to be addressed by the plan of action are identified. What the plan covers is known.
A plan of action is developed to correct deficiencies and reduce or eliminate vulnerabilities. A documented corrective plan exists.
The plan of action is implemented to correct deficiencies and reduce or eliminate vulnerabilities. The corrective actions are carried out.
The three objectives are identify, develop, and implement. The common gap is at objective [c], where plans of action are written and maintained but the corrective actions are not carried through, so deficiencies persist behind a documented intention to fix them. The assessor looks for all three: identified deficiencies, a developed plan, and its implementation.
3Failure Patterns
The failures are about plans that are written but not carried out.
Plans without implementation
A plan of action that documents corrective actions but is never carried through leaves the deficiencies open. Implementation is what closes them.
Deficiencies not identified
Without identifying the deficiencies and vulnerabilities to address, the plan has no defined scope. Identification sets what the plan covers.
No structured plan
Correcting deficiencies ad hoc, without a documented plan of action, makes progress hard to track and closure hard to show. A developed plan gives the correction structure and accountability.
4Ownership
This is a security and compliance-owned control with IT executing the corrections.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Identifies deficiencies and develops the plans of action. Owns the plan of action records. |
| IT and system administrator | Implements the corrective actions in the plan. |
| Program lead | Tracks the plan to closure and confirms corrections are carried out. |
5Tooling
The control is delivered by a plan-of-action process that identifies, plans, and closes deficiencies.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Deficiency identification | The scope of what the plan addresses. |
| [b] | Plan of action document | Documented corrective actions. |
| [c] | Corrective action execution and tracking | Implementation of the plan to closure. |
The caveat is that the plan has to be implemented, not just developed and maintained. A well-documented plan of action that never drives corrective action leaves the deficiencies open. The assessor examines all three objectives, so identification, development, and implementation all have to hold.
6Evidence
The satisfied version of 3.12.2 shows plans of action developed and carried through.
| Evidence | What it demonstrates |
|---|---|
| Identified deficiencies | Objective [a]. What the plan addresses. |
| Plan of action document | Objective [b]. A developed corrective plan. |
| Corrective action records | Objective [c]. The plan implemented to closure. |
The evidence should show identified deficiencies, a developed plan of action, and records of that plan implemented. The plan together with the corrective action records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
A plan of action is a roadmap, not a destination
Writing a plan is easy; carrying it through is the work, so this three-point control asks that deficiencies be identified, planned, and actually corrected. Building a plan-of-action process that closes gaps is part of the onsite readiness work this practice does, and fittingly, this control about plans of action is itself one that cannot be deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.12.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.12.2[a] through 3.12.2[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing CA.L2-3.12.2 among the three-point basic security requirements. ecfr.gov