System Security and Privacy Plans
Description
a. Develop security and privacy plans for the system that: b. Distribute copies of the plans and communicate subsequent changes to the plans to [organization-defined parameter]; c. Review the plans [organization-defined parameter]; d. Update the plans to address changes to the system and environment of operation or problems identified during plan implementation or control assessments; and e. Protect the plans from unauthorized disclosure and modification.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 6 in NIST Cybersecurity Framework 2.0
- ID.AM-03Representations of the organization's authorized network communication and internal and external network data flows are maintained
- ID.AM-08Systems, hardware, software, services, and data are managed throughout their life cycles
- ID.IM-01Improvements are identified from evaluations
- ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ID.IM-03Improvements are identified from execution of operational processes, procedures, and activities
- ID.IM-04Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Cite as SafeMode Space, nist-80053-rev5 PL-2.