Why: The practice's remediation tracking — findings, owners, dates, windows held or missed — is the same shape of record a plan of action and milestones draws on for its known-vulnerability entries, so the practice's normal operation keeps that portion of the plan supplied with current, truthful input.
What this does not claim: Provides evidence relevant to the requirement rather than implementing it. A plan of action and milestones is a governance document spanning weaknesses in any security requirement, produced and updated through the assessment process; a patch queue does not become one by renaming it, and deficiencies outside vulnerability management never appear in the practice's records at all.
- Roll remediation status for significant open vulnerabilities into plan-of-action entries with milestones
- Feed missed-window findings into the plan's update cycle
- Plan-of-action entries traceable to the remediation tracker
- Update records showing vulnerability items closed with evidence
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06