POAM Template - R3.0 changes #119
Replies: 4 comments 2 replies
-
|
We have recently reviewed the POA&M Template from 2025-12-05 and also request clarification on why "Service Name" was removed when its purpose is to specify which exact service(s) are affected for each POA&M ID row? Additionally, We have noted the following changes: Added
Changed
Removed from "Open POA&M Items", "Closed POA&M Items" and "Configuration Findings" tab:
|
Beta Was this translation helpful? Give feedback.
-
|
I'm trying to track down more info on this; the changes resulted from multiple years of feedback gathering and some of the background appears to have been lost with some of our staff. Lots of folks apparently found that column very confusing and it created more issues than it helped. In the interim I'll say that the template contains the minimum expected information; if a cloud service provider has a good reason to include additional information then they should do so. No one should feel like removing this from the template means they aren't allowed to track and report on it if they found it useful. |
Beta Was this translation helpful? Give feedback.
-
|
Coming back on this to close this question out - this column was inadvertently added originally, did not have lots of guidance and support, and was thus removed. FR does not have any issue with folks adding it back in if a particular CSP wants to or an agency customer wants it from them. We'll revisit the POAM fields again as part of our upcoming audit and transition to machine-readability for Rev5 materials and look to provide more instructions about optional fields. |
Beta Was this translation helpful? Give feedback.
-
|
Paul - Ah thank you for this additional context and clarity. As a follow-up question, given that R3.0 is the latest version of the template does the FedRAMP PMO archive the format of the R2.1 template anywhere for reference? I have looked and cannot seem to find it. These details are important for a software vendor (like ourselves) looking to ensure we support multiple formats as it looks like both will be use for some time. Thank you very much. Blake |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi - I had a question about the R3.0 POAM template (Excel). I don't know if this is the correct place for this question, if not, please let me know.
We've noticed that Service Name was removed from the R3.0 version of the template, but it appeared in the R2.1 version.
We support customers who still may be using R2.1 and basically had three questions:
Added Instructions Tab, consolidated reporting fields, and simplified input requirements._
Thank you for any insight. We provide software to customers who may be relying on the older version of the template.
Blake
Beta Was this translation helpful? Give feedback.
All reactions