Skip to content
Security
Command

/poam-review

Review and manage Plan of Action & Milestones (POA&M)

From plugin
trust-center
367139 skills139 commands1 MCP
Install
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/poam-review

Context preview

What this command does when you run it.

Review and manage Plan of Action & Milestones (POA&M)

Command definition

poam-review.md
description: Review and manage Plan of Action & Milestones (POA&M)

POA&M Review

Analyzes and provides guidance on FedRAMP Plan of Action & Milestones.

Arguments

  • `$1` - POA&M file or action (required)
  • `$2` - Analysis type (optional: gaps, priorities, aging)

POA&M Requirements

Each POA&M item must include:

  • Weakness description
  • Point of contact
  • Resources required
  • Scheduled completion date
  • Milestones with dates
  • Status updates
  • Risk level (High/Moderate/Low)

Analysis Types

  • **gaps** - Identify missing required fields
  • **priorities** - Rank items by risk and due date
  • **aging** - Flag overdue items and extensions needed

FedRAMP POA&M Rules

  • High vulnerabilities: 30 days to remediate
  • Moderate vulnerabilities: 90 days to remediate
  • Low vulnerabilities: 180 days to remediate
  • Operational requirements may extend timelines

Example

/fedramp-rev5:poam-review ./poam.xlsx priorities
Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked
Stats
367
Stars
0
Views
82
Forks
Active
Maintenance
JavaScript
Language
1d ago
Last commit
7mo ago
Created

Repo: GRCEngClub/claude-grc-engineering