Step 6 — Building the Story: Security Assessment Reports and POA&Ms
The report is an argument addressed to one person who has to make a decision — not a data dump addressed to nobody
A security assessment report has an audience of one. It is written for the person who must decide whether to authorize, and every structural choice follows from that.
They will read the first page carefully and the rest selectively. They cannot verify the technical content themselves. They need to know what risk they are being asked to carry, in words they can repeat to their own director.
Write the report so that if the reader stopped after page one, they could still decide.
What a SAR Is For#
NIST's definition is spare and correct:
Provides a disciplined and structured approach for documenting the findings of the assessor and the recommendations for correcting any identified vulnerabilities in the security controls.
CNSSI 4009-2022, via the NIST glossaryFindings and recommendations.1 Not a transcript. Not the evidence itself — that is attached, not embedded. The report is the assessor's judgment, organized for someone else to act on.
What Goes in It#
| Section | Purpose |
|---|---|
| Executive summary | The overall picture, the residual risk in plain language, the recommendation |
| Scope and boundary | What was assessed — and, explicitly, what was not |
| Methodology | How results were reached, so they are reproducible |
| Control results | The full set, by control and lettered part |
| Findings | The failures, each with evidence and the gap in one sentence |
| Risks | The risk statements derived from findings — Step 5 |
| POA&M | What will be done, by whom, by when |
| Limitations | What the assessment could not establish, and why |
Order matters. Findings sorted by control ID is the assessor's convenience; findings sorted by residual risk is the reader's. Use the second.
The Executive Summary#
Written last, read first. Three things and nothing else:
- The overall pictureTwo sentences. Is this system in reasonable shape, or not?
- The residual risk, in plain languageWhat the authorizer would be carrying, and why it is at that level
- The recommendationAuthorize, authorize with these conditions, or do not — and what would change the answer
No control IDs. No counts of findings by severity. If the reader stopped here, they should still be able to decide.
Stating Residual Risk Plainly#
Report the risk, not the arithmetic. A rating without a sentence explaining what it means operationally is a number nobody can act on.
| Rating alone | Rating with meaning |
|---|---|
| Residual risk: High | Residual risk: High — former staff may retain access to case records for up to 90 days after departure, and the estate-wide access review that would catch it does not yet run. |
How the rating was produced — the three questions, the matrices — is in How Dangerous, How Exposed, What Remains. The report cites it; it does not re-derive it.
What a POA&M Is#
A document that identifies tasks that need to be accomplished. It details resources required to accomplish the elements of the plan, milestones for meeting the tasks, and the scheduled completion dates for the milestones.
NIST SP 800-53 Rev. 5, via the NIST glossaryTasks, resources, milestones, dates.2 A commitment register. The fields that make it honest:
| Field | Why it matters |
|---|---|
| The risk or finding it addresses | So the action can be traced to why it exists |
| The action | Specific enough that "done" is verifiable |
| The owner, by role | Roles survive reorganizations |
| Milestone dates | Agreed by the owner before they were written |
| Status | Current, not aspirational |
| Residual risk carried until closure | The field usually missing — and the one that makes the POA&M honest |
That last row is the point. Until the action completes, someone is carrying the risk. The POA&M should say who, and the authorizer should be accepting it knowingly.4
Milestones People Actually Meet#
The Authorization Package#
Scroll sideways to see the full diagram →
What physically reaches the authorizer: the SAR, the POA&M, the system security documentation, and evidence for inherited controls — together with the recommendation. ITSG-33 frames the package as the assembled outputs supporting the authorization decision;3 Step 7 covers what happens to it.
Where CtrlFort Fits#
Reports assembled by hand drift from the evidence beneath them. A number is transcribed wrong, a finding is reworded into something softer, a POA&M date is typed into a table that is not connected to the risk it addresses.
In CtrlFort Assess the report is drafted from the assessment record. Control results, findings with their evidence links, and risk statements with their ratings are the same linked objects the assessor worked in, and CtrlFort AI drafts the findings, the recommendations, the executive summary and the full report from that structured result — so the SAR cannot say something the assessment did not find, and the assessor edits a draft that is already true.
Every report can answer the five questions an authorizer will ask: what was assessed, what evidence was reviewed, what was missing, how the determination was reached, and what risk remains. Risks promoted from the assessment carry their owners into the risk register, where review dates keep an accepted risk visible for the life of the system.5
Final Thoughts#
One reader. One decision. Write the report for that, attach the evidence, and let the POA&M be a list of promises somebody actually made.
Previous: Step 5 — From Finding to Risk Statement · Next: Step 7 — Authorization Decisions
Frequently Asked Questions#
What is the difference between a SAR and an audit report?#
An audit report tests conformance to a standard and reports to a governance body. A SAR documents an assessor's findings and recommendations about one system, addressed to the person deciding whether to operate it. Similar evidence; different question, different reader.
Is a POA&M the same as a risk register?#
No. A POA&M tracks the remediation commitments from one assessment. A risk register holds every risk the organization is managing, from all sources, for the life of the system. Risks from the POA&M are promoted into the register; the POA&M itself closes when its actions do.
Who writes the executive summary?#
The assessor, last, after the rest of the report exists. It states their overall judgment and recommendation. The system owner does not write the summary of their own system's assessment.
What happens if a POA&M milestone is missed?#
The slippage is made visible, the owner proposes a new date, and the authorizer re-accepts the risk carried in the meantime — explicitly. Quietly re-dating a milestone is how a POA&M becomes fiction.
References#
- Security Assessment Report — glossary entry, citing CNSSI 4009-2022 ↩National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/security_assessment_report
- Plan of Action and Milestones — glossary entry, citing NIST SP 800-53 Rev. 5 ↩National Institute of Standards and Technology · https://csrc.nist.gov/glossary/term/plan_of_action_and_milestones
- ITSG-33 Annex 2 — Information System Security Risk Management Activities ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/annex-2-information-system-security-risk-management-activities-itsg-33
- ITSP.50.105 — Guidance on cloud security assessment and authorization ↩Canadian Centre for Cyber Security · https://www.cyber.gc.ca/en/guidance/guidance-cloud-security-assessment-and-authorization-itsp50105
- NIST SP 800-37 Rev. 2 — Risk Management Framework for Information Systems and Organizations ↩National Institute of Standards and Technology · https://csrc.nist.gov/pubs/sp/800/37/r2/final