Information Security and Privacy Resources
Description
a. Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document all exceptions to this requirement; b. Prepare documentation required for addressing information security and privacy programs in capital planning and investment requests in accordance with applicable laws, executive orders, directives, policies, regulations, standards; and c. Make available for expenditure, the planned information security and privacy resources.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 3 in NIST Cybersecurity Framework 2.0
- GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
- GV.RR-03Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
- PR.IR-04Adequate resource capacity to ensure availability is maintained
Cite as SafeMode Space, nist-80053-rev5 PM-3.