PM-8 Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan
Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- The critical infrastructure and key resources protection plan · Policy repository / GRC workspace
- The sections addressing information security and privacy issues within that plan · Policy repository / GRC workspace
- Identification of the organisation's critical infrastructure and key resources that the plan covers · Policy repository / GRC workspace
- Update records showing the plan is maintained as the infrastructure or the threat changes · Policy repository / GRC workspace
- Evidence of coordination with the sector or national bodies the plan sits under · Policy repository / GRC workspace
First move
Common gaps auditors find
- Plan addresses physical protection of infrastructure while information security and privacy issues are omitted
- Critical infrastructure identified once with no reassessment as dependencies shifted to third parties
- Plan held by facilities or operations with security and privacy functions never consulted
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-7 Enterprise Architecture. Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations and assets, individuals, other organizations, and the Nation · PM-9 Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk