PM-4
Program Management
Plan of Action and Milestones Process
Description
a. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems: b. Review plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 3 in NIST Cybersecurity Framework 2.0
- GV.OV-03Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
- ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ID.IM-03Improvements are identified from execution of operational processes, procedures, and activities
Cite as SafeMode Space, nist-80053-rev5 PM-4.