PM-1
Program Management
Information Security Program Plan
Description
a. Develop and disseminate an organization-wide information security program plan that: b. Review and update the organization-wide information security program plan [organization-defined parameter] and following [organization-defined parameter] ; and c. Protect the information security program plan from unauthorized disclosure and modification.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 8 in NIST Cybersecurity Framework 2.0
- GV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
- GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- GV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
- GV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
- GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- ID.IM-01Improvements are identified from evaluations
- ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ID.IM-03Improvements are identified from execution of operational processes, procedures, and activities
Cite as SafeMode Space, nist-80053-rev5 PM-1.