Why: The practice's remediation tracking — findings with owners and windows, plus an exception register with expiry dates — produces exactly the deficiency-correction records the vulnerability slice of a plan of action draws on and closes against.
What this does not claim: Provides evidence relevant to the requirement rather than implementing it: a plan of action spans every kind of deficiency — policy gaps, training shortfalls, assessment findings — not just scanner output, and it must exist as a maintained document with milestones regardless of how well the underlying tickets flow. Feeding the ledger is not the same as keeping it.
- Promote overdue and excepted findings into plan-of-action entries with owners and milestone dates
- Close plan-of-action items using remediation records as the evidence
- Plan-of-action entries traceable to scan findings
- Closure evidence drawn from remediation records
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06