Management Action Plan
Detects management action plans documenting remediation timelines for audit findings and vulnerabilities.
- Type
- regex
- Confidence
- medium
- Confidence justification
- Medium confidence: keyword-based detection requires corroborative evidence for accurate identification.
- Jurisdictions
- global
- Regulations
- IPA 2009 (Qld), Privacy Act 1988 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- DISP, ISO 27001, NIST CSF
- Data categories
- audit, governance
- Scope
- narrow
- Risk rating
- 4
Should match
Management action plan— Low-tier probe - action-plan title without remediation detailManagement action plan: corrective action owner and target date for closure.— Medium-tier probe - remediation tracking without a classified audit findingManagement action plan: high risk finding, required action, responsible owner, due date, and closure status.— High-tier probe - classified finding plus remediation tracking
Should not match
Action plan for the marketing campaign— Marketing-plan siblingManagement meeting agenda— Management prose without an action planThe public governance page links to a management action plan.— Public link mentions only the document titleTemplate example: management action plan for a high risk finding with required action, owner, due date, and closure.— Template contains otherwise high-tier evidence
Known false positives
- Generic action plan in non-audit contexts. Mitigation: Require audit-specific terms like remediation, finding closure, or management response.