PM-4: Plan of Action and Milestones Process

Privacy Baseline:  Yes 

DIR Required By:  07/20/2023 

Review Date:  07/31/2024 

  • It is the responsibility of the Tarleton President/CEO, in coordination with the Tarleton Chief Information Security Officer (CISO), to implement a process for ensuring that plans of action and milestones for the security program and associated Tarleton information resources: 
    • Are developed and maintained, 
    • Document the remedial information security actions to adequately respond to risk to Tarleton operations and assets, individuals, other organizations, and 
    • Are reported in accordance with OMB FISMA reporting requirements, as applicable. 
  • The Tarleton CIO, in coordination with the Tarleton CISO, shall review plans of action and milestones for consistency with the university risk management strategy and priorities for risk response actions. 

References/Additional Resources

None.  See any applicable internal procedures.