Skip to content

Nist 800 53 Pl

FieldValue
TypeSkill Resource
Source~/.copilot/skills/security/references/ato/nist-800-53-pl.json
DescriptionNot specified

Source Content

{
"catalog_uuid": "ea7c7688-79c5-463b-a91b-0650f2d98623",
"catalog_title": "Electronic (OSCAL) Version of NIST SP 800-53 Rev 5.2.0 Controls and SP 800-53A Rev 5.2.0 Assessment Procedures",
"catalog_version": "5.2.0",
"group": {
"id": "pl",
"class": "family",
"title": "Planning",
"props": [
{
"name": "label",
"value": "PL"
}
],
"controls": [
{
"id": "pl-1",
"class": "SP800-53",
"title": "Policy and Procedures",
"params": [
{
"id": "pl-1_prm_1",
"props": [
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "pl-01_odp.01"
},
{
"name": "aggregates",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "pl-01_odp.02"
}
],
"label": "organization-defined personnel or roles"
},
{
"id": "pl-01_odp.01",
"props": [
{
"name": "label",
"value": "PL-01_ODP[01]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom the planning policy is to be disseminated is/are defined;"
}
]
},
{
"id": "pl-01_odp.02",
"props": [
{
"name": "label",
"value": "PL-01_ODP[02]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to whom the planning procedures are to be disseminated is/are defined;"
}
]
},
{
"id": "pl-01_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pl-1_prm_2"
},
{
"name": "label",
"value": "PL-01_ODP[03]",
"class": "sp800-53a"
}
],
"select": {
"how-many": "one-or-more",
"choice": [
"organization-level",
"mission/business process-level",
"system-level"
]
}
},
{
"id": "pl-01_odp.04",
"props": [
{
"name": "alt-identifier",
"value": "pl-1_prm_3"
},
{
"name": "label",
"value": "PL-01_ODP[04]",
"class": "sp800-53a"
}
],
"label": "official",
"guidelines": [
{
"prose": "an official to manage the planning policy and procedures is defined;"
}
]
},
{
"id": "pl-01_odp.05",
"props": [
{
"name": "alt-identifier",
"value": "pl-1_prm_4"
},
{
"name": "label",
"value": "PL-01_ODP[05]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency with which the current planning policy is reviewed and updated is defined;"
}
]
},
{
"id": "pl-01_odp.06",
"props": [
{
"name": "alt-identifier",
"value": "pl-1_prm_5"
},
{
"name": "label",
"value": "PL-01_ODP[06]",
"class": "sp800-53a"
}
],
"label": "events",
"guidelines": [
{
"prose": "events that would require the current planning policy to be reviewed and updated are defined;"
}
]
},
{
"id": "pl-01_odp.07",
"props": [
{
"name": "alt-identifier",
"value": "pl-1_prm_6"
},
{
"name": "label",
"value": "PL-01_ODP[07]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "the frequency with which the current planning procedures are reviewed and updated is defined;"
}
]
},
{
"id": "pl-01_odp.08",
"props": [
{
"name": "alt-identifier",
"value": "pl-1_prm_7"
},
{
"name": "label",
"value": "PL-01_ODP[08]",
"class": "sp800-53a"
}
],
"label": "events",
"guidelines": [
{
"prose": "events that would require procedures to be reviewed and updated are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-01",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-1"
},
{
"name": "label",
"value": "PL-01",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#c7ac44e8-10db-4b64-b2b9-9e32ec1efed0",
"rel": "reference"
},
{
"href": "#30eb758a-2707-4bca-90ad-949a74d4eb16",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#4c0ec2ee-a0d6-428a-9043-4504bc3ade6f",
"rel": "reference"
},
{
"href": "#pm-9",
"rel": "related"
},
{
"href": "#ps-8",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
}
],
"parts": [
{
"id": "pl-1_smt",
"name": "statement",
"parts": [
{
"id": "pl-1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Develop, document, and disseminate to {{ insert: param, pl-1_prm_1 }}:",
"parts": [
{
"id": "pl-1_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "{{ insert: param, pl-01_odp.03 }} planning policy that:",
"parts": [
{
"id": "pl-1_smt.a.1.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and"
},
{
"id": "pl-1_smt.a.1.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and"
}
]
},
{
"id": "pl-1_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Procedures to facilitate the implementation of the planning policy and the associated planning controls;"
}
]
},
{
"id": "pl-1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Designate an {{ insert: param, pl-01_odp.04 }} to manage the development, documentation, and dissemination of the planning policy and procedures; and"
},
{
"id": "pl-1_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Review and update the current planning:",
"parts": [
{
"id": "pl-1_smt.c.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Policy {{ insert: param, pl-01_odp.05 }} and following {{ insert: param, pl-01_odp.06 }} ; and"
},
{
"id": "pl-1_smt.c.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Procedures {{ insert: param, pl-01_odp.07 }} and following {{ insert: param, pl-01_odp.08 }}."
}
]
}
]
},
{
"id": "pl-1_gdn",
"name": "guidance",
"prose": "Planning policy and procedures for the controls in the PL family implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on their development. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission level or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies that reflect the complex nature of organizations. Procedures can be established for security and privacy programs, for mission/business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to planning policy and procedures include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure."
},
{
"id": "pl-1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.[01]",
"class": "sp800-53a"
}
],
"prose": "a planning policy is developed and documented.",
"links": [
{
"href": "#pl-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.[02]",
"class": "sp800-53a"
}
],
"prose": "the planning policy is disseminated to {{ insert: param, pl-01_odp.01 }};",
"links": [
{
"href": "#pl-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.[03]",
"class": "sp800-53a"
}
],
"prose": "planning procedures to facilitate the implementation of the planning policy and associated planning controls are developed and documented;",
"links": [
{
"href": "#pl-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.[04]",
"class": "sp800-53a"
}
],
"prose": "the planning procedures are disseminated to {{ insert: param, pl-01_odp.02 }};",
"links": [
{
"href": "#pl-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.a.1.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.a.1.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[01]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses purpose;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[02]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses scope;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.a-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[03]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses roles;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.a-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[04]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses responsibilities;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.a-5",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[05]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses management commitment;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.a-6",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[06]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses coordination among organizational entities;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.a-7",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(a)[07]",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy addresses compliance;",
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt.a.1.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.a.1.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01a.01(b)",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.03 }} planning policy is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines;",
"links": [
{
"href": "#pl-1_smt.a.1.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt.a.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01b.",
"class": "sp800-53a"
}
],
"prose": "the {{ insert: param, pl-01_odp.04 }} is designated to manage the development, documentation, and dissemination of the planning policy and procedures;",
"links": [
{
"href": "#pl-1_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.c.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.c.1-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.01[01]",
"class": "sp800-53a"
}
],
"prose": "the current planning policy is reviewed and updated {{ insert: param, pl-01_odp.05 }};",
"links": [
{
"href": "#pl-1_smt.c.1",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.c.1-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.01[02]",
"class": "sp800-53a"
}
],
"prose": "the current planning policy is reviewed and updated following {{ insert: param, pl-01_odp.06 }};",
"links": [
{
"href": "#pl-1_smt.c.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt.c.1",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.c.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-1_obj.c.2-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.02[01]",
"class": "sp800-53a"
}
],
"prose": "the current planning procedures are reviewed and updated {{ insert: param, pl-01_odp.07 }};",
"links": [
{
"href": "#pl-1_smt.c.2",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_obj.c.2-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-01c.02[02]",
"class": "sp800-53a"
}
],
"prose": "the current planning procedures are reviewed and updated following {{ insert: param, pl-01_odp.08 }}.",
"links": [
{
"href": "#pl-1_smt.c.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt.c.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-01-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Planning policy and procedures\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pl-1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-01-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with planning responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
}
]
},
{
"id": "pl-2",
"class": "SP800-53",
"title": "System Security and Privacy Plans",
"params": [
{
"id": "pl-02_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pl-2_prm_1"
},
{
"name": "label",
"value": "PL-02_ODP[01]",
"class": "sp800-53a"
}
],
"label": "individuals or groups",
"guidelines": [
{
"prose": "individuals or groups with whom security and privacy-related activities affecting the system that require planning and coordination is/are assigned;"
}
]
},
{
"id": "pl-02_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pl-2_prm_2"
},
{
"name": "label",
"value": "PL-02_ODP[02]",
"class": "sp800-53a"
}
],
"label": "personnel or roles",
"guidelines": [
{
"prose": "personnel or roles to receive distributed copies of the system security and privacy plans is/are assigned;"
}
]
},
{
"id": "pl-02_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pl-2_prm_3"
},
{
"name": "label",
"value": "PL-02_ODP[03]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "frequency to review system security and privacy plans is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-02",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-2"
},
{
"name": "label",
"value": "PL-02",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#30eb758a-2707-4bca-90ad-949a74d4eb16",
"rel": "reference"
},
{
"href": "#482e4c99-9dc4-41ad-bba8-0f3f0032c1f8",
"rel": "reference"
},
{
"href": "#e3cc0520-a366-4fc9-abc2-5272db7e3564",
"rel": "reference"
},
{
"href": "#61ccf0f4-d3e7-42db-9796-ce6cb1c85989",
"rel": "reference"
},
{
"href": "#ac-2",
"rel": "related"
},
{
"href": "#ac-6",
"rel": "related"
},
{
"href": "#ac-14",
"rel": "related"
},
{
"href": "#ac-17",
"rel": "related"
},
{
"href": "#ac-20",
"rel": "related"
},
{
"href": "#ca-2",
"rel": "related"
},
{
"href": "#ca-3",
"rel": "related"
},
{
"href": "#ca-7",
"rel": "related"
},
{
"href": "#cm-9",
"rel": "related"
},
{
"href": "#cm-13",
"rel": "related"
},
{
"href": "#cp-2",
"rel": "related"
},
{
"href": "#cp-4",
"rel": "related"
},
{
"href": "#ir-4",
"rel": "related"
},
{
"href": "#ir-8",
"rel": "related"
},
{
"href": "#ma-4",
"rel": "related"
},
{
"href": "#ma-5",
"rel": "related"
},
{
"href": "#mp-4",
"rel": "related"
},
{
"href": "#mp-5",
"rel": "related"
},
{
"href": "#pl-7",
"rel": "related"
},
{
"href": "#pl-8",
"rel": "related"
},
{
"href": "#pl-10",
"rel": "related"
},
{
"href": "#pl-11",
"rel": "related"
},
{
"href": "#pm-1",
"rel": "related"
},
{
"href": "#pm-7",
"rel": "related"
},
{
"href": "#pm-8",
"rel": "related"
},
{
"href": "#pm-9",
"rel": "related"
},
{
"href": "#pm-10",
"rel": "related"
},
{
"href": "#pm-11",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#ra-8",
"rel": "related"
},
{
"href": "#ra-9",
"rel": "related"
},
{
"href": "#sa-5",
"rel": "related"
},
{
"href": "#sa-17",
"rel": "related"
},
{
"href": "#sa-22",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
},
{
"href": "#sr-2",
"rel": "related"
},
{
"href": "#sr-4",
"rel": "related"
}
],
"parts": [
{
"id": "pl-2_smt",
"name": "statement",
"parts": [
{
"id": "pl-2_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Develop security and privacy plans for the system that:",
"parts": [
{
"id": "pl-2_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Are consistent with the organization\u2019s enterprise architecture;"
},
{
"id": "pl-2_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Explicitly define the constituent system components;"
},
{
"id": "pl-2_smt.a.3",
"name": "item",
"props": [
{
"name": "label",
"value": "3."
}
],
"prose": "Describe the operational context of the system in terms of mission and business processes;"
},
{
"id": "pl-2_smt.a.4",
"name": "item",
"props": [
{
"name": "label",
"value": "4."
}
],
"prose": "Identify the individuals that fulfill system roles and responsibilities;"
},
{
"id": "pl-2_smt.a.5",
"name": "item",
"props": [
{
"name": "label",
"value": "5."
}
],
"prose": "Identify the information types processed, stored, and transmitted by the system;"
},
{
"id": "pl-2_smt.a.6",
"name": "item",
"props": [
{
"name": "label",
"value": "6."
}
],
"prose": "Provide the security categorization of the system, including supporting rationale;"
},
{
"id": "pl-2_smt.a.7",
"name": "item",
"props": [
{
"name": "label",
"value": "7."
}
],
"prose": "Describe any specific threats to the system that are of concern to the organization;"
},
{
"id": "pl-2_smt.a.8",
"name": "item",
"props": [
{
"name": "label",
"value": "8."
}
],
"prose": "Provide the results of a privacy risk assessment for systems processing personally identifiable information;"
},
{
"id": "pl-2_smt.a.9",
"name": "item",
"props": [
{
"name": "label",
"value": "9."
}
],
"prose": "Describe the operational environment for the system and any dependencies on or connections to other systems or system components;"
},
{
"id": "pl-2_smt.a.10",
"name": "item",
"props": [
{
"name": "label",
"value": "10."
}
],
"prose": "Provide an overview of the security and privacy requirements for the system;"
},
{
"id": "pl-2_smt.a.11",
"name": "item",
"props": [
{
"name": "label",
"value": "11."
}
],
"prose": "Identify any relevant control baselines or overlays, if applicable;"
},
{
"id": "pl-2_smt.a.12",
"name": "item",
"props": [
{
"name": "label",
"value": "12."
}
],
"prose": "Describe the controls in place or planned for meeting the security and privacy requirements, including a rationale for any tailoring decisions;"
},
{
"id": "pl-2_smt.a.13",
"name": "item",
"props": [
{
"name": "label",
"value": "13."
}
],
"prose": "Include risk determinations for security and privacy architecture and design decisions;"
},
{
"id": "pl-2_smt.a.14",
"name": "item",
"props": [
{
"name": "label",
"value": "14."
}
],
"prose": "Include security- and privacy-related activities affecting the system that require planning and coordination with {{ insert: param, pl-02_odp.01 }} ; and"
},
{
"id": "pl-2_smt.a.15",
"name": "item",
"props": [
{
"name": "label",
"value": "15."
}
],
"prose": "Are reviewed and approved by the authorizing official or designated representative prior to plan implementation."
}
]
},
{
"id": "pl-2_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Distribute copies of the plans and communicate subsequent changes to the plans to {{ insert: param, pl-02_odp.02 }};"
},
{
"id": "pl-2_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Review the plans {{ insert: param, pl-02_odp.03 }};"
},
{
"id": "pl-2_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Update the plans to address changes to the system and environment of operation or problems identified during plan implementation or control assessments; and"
},
{
"id": "pl-2_smt.e",
"name": "item",
"props": [
{
"name": "label",
"value": "e."
}
],
"prose": "Protect the plans from unauthorized disclosure and modification."
}
]
},
{
"id": "pl-2_gdn",
"name": "guidance",
"prose": "System security and privacy plans are scoped to the system and system components within the defined authorization boundary and contain an overview of the security and privacy requirements for the system and the controls selected to satisfy the requirements. The plans describe the intended application of each selected control in the context of the system with a sufficient level of detail to correctly implement the control and to subsequently assess the effectiveness of the control. The control documentation describes how system-specific and hybrid controls are implemented and the plans and expectations regarding the functionality of the system. System security and privacy plans can also be used in the design and development of systems in support of life cycle-based security and privacy engineering processes. System security and privacy plans are living documents that are updated and adapted throughout the system development life cycle (e.g., during capability determination, analysis of alternatives, requests for proposal, and design reviews). [Section 2.1](#c3397cc9-83c6-4459-adb2-836739dc1b94) describes the different types of requirements that are relevant to organizations during the system development life cycle and the relationship between requirements and controls.\n\nOrganizations may develop a single, integrated security and privacy plan or maintain separate plans. Security and privacy plans relate security and privacy requirements to a set of controls and control enhancements. The plans describe how the controls and control enhancements meet the security and privacy requirements but do not provide detailed, technical descriptions of the design or implementation of the controls and control enhancements. Security and privacy plans contain sufficient information (including specifications of control parameter values for selection and assignment operations explicitly or by reference) to enable a design and implementation that is unambiguously compliant with the intent of the plans and subsequent determinations of risk to organizational operations and assets, individuals, other organizations, and the Nation if the plan is implemented.\n\nSecurity and privacy plans need not be single documents. The plans can be a collection of various documents, including documents that already exist. Effective security and privacy plans make extensive use of references to policies, procedures, and additional documents, including design and implementation specifications where more detailed information can be obtained. The use of references helps reduce the documentation associated with security and privacy programs and maintains the security- and privacy-related information in other established management and operational areas, including enterprise architecture, system development life cycle, systems engineering, and acquisition. Security and privacy plans need not contain detailed contingency plan or incident response plan information but can instead provide\u2014explicitly or by reference\u2014sufficient information to define what needs to be accomplished by those plans.\n\nSecurity- and privacy-related activities that may require coordination and planning with other individuals or groups within the organization include assessments, audits, inspections, hardware and software maintenance, acquisition and supply chain risk management, patch management, and contingency plan testing. Planning and coordination include emergency and nonemergency (i.e., planned or non-urgent unplanned) situations. The process defined by organizations to plan and coordinate security- and privacy-related activities can also be included in other documents, as appropriate."
},
{
"id": "pl-2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.01",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.1-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.01[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that is consistent with the organization\u2019s enterprise architecture;",
"links": [
{
"href": "#pl-2_smt.a.1",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.1-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.01[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that is consistent with the organization\u2019s enterprise architecture;",
"links": [
{
"href": "#pl-2_smt.a.1",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.1",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.02",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.2-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.02[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that explicitly defines the constituent system components;",
"links": [
{
"href": "#pl-2_smt.a.2",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.2-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.02[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that explicitly defines the constituent system components;",
"links": [
{
"href": "#pl-2_smt.a.2",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.2",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.03",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.3-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.03[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that describes the operational context of the system in terms of mission and business processes;",
"links": [
{
"href": "#pl-2_smt.a.3",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.3-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.03[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that describes the operational context of the system in terms of mission and business processes;",
"links": [
{
"href": "#pl-2_smt.a.3",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.3",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.04",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.4-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.04[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that identifies the individuals that fulfill system roles and responsibilities;",
"links": [
{
"href": "#pl-2_smt.a.4",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.4-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.04[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that identifies the individuals that fulfill system roles and responsibilities;",
"links": [
{
"href": "#pl-2_smt.a.4",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.4",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.5",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.05",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.5-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.05[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that identifies the information types processed, stored, and transmitted by the system;",
"links": [
{
"href": "#pl-2_smt.a.5",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.5-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.05[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that identifies the information types processed, stored, and transmitted by the system;",
"links": [
{
"href": "#pl-2_smt.a.5",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.5",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.6",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.06",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.6-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.06[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that provides the security categorization of the system, including supporting rationale;",
"links": [
{
"href": "#pl-2_smt.a.6",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.6-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.06[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that provides the security categorization of the system, including supporting rationale;",
"links": [
{
"href": "#pl-2_smt.a.6",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.6",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.7",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.07",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.7-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.07[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that describes any specific threats to the system that are of concern to the organization;",
"links": [
{
"href": "#pl-2_smt.a.7",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.7-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.07[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that describes any specific threats to the system that are of concern to the organization;",
"links": [
{
"href": "#pl-2_smt.a.7",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.7",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.8",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.08",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.8-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.08[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that provides the results of a privacy risk assessment for systems processing personally identifiable information;",
"links": [
{
"href": "#pl-2_smt.a.8",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.8-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.08[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that provides the results of a privacy risk assessment for systems processing personally identifiable information;",
"links": [
{
"href": "#pl-2_smt.a.8",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.8",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.9",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.09",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.9-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.09[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that describes the operational environment for the system and any dependencies on or connections to other systems or system components;",
"links": [
{
"href": "#pl-2_smt.a.9",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.9-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.09[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that describes the operational environment for the system and any dependencies on or connections to other systems or system components;",
"links": [
{
"href": "#pl-2_smt.a.9",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.9",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.10",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.10",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.10-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.10[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that provides an overview of the security requirements for the system;",
"links": [
{
"href": "#pl-2_smt.a.10",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.10-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.10[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that provides an overview of the privacy requirements for the system;",
"links": [
{
"href": "#pl-2_smt.a.10",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.10",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.11",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.11",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.11-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.11[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that identifies any relevant control baselines or overlays, if applicable;",
"links": [
{
"href": "#pl-2_smt.a.11",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.11-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.11[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that identifies any relevant control baselines or overlays, if applicable;",
"links": [
{
"href": "#pl-2_smt.a.11",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.11",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.12",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.12",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.12-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.12[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that describes the controls in place or planned for meeting the security requirements, including rationale for any tailoring decisions;",
"links": [
{
"href": "#pl-2_smt.a.12",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.12-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.12[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that describes the controls in place or planned for meeting the privacy requirements, including rationale for any tailoring decisions;",
"links": [
{
"href": "#pl-2_smt.a.12",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.12",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.13",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.13",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.13-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.13[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that includes risk determinations for security architecture and design decisions;",
"links": [
{
"href": "#pl-2_smt.a.13",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.13-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.13[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that includes risk determinations for privacy architecture and design decisions;",
"links": [
{
"href": "#pl-2_smt.a.13",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.13",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.14",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.14",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.14-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.14[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that includes security-related activities affecting the system that require planning and coordination with {{ insert: param, pl-02_odp.01 }};",
"links": [
{
"href": "#pl-2_smt.a.14",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.14-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.14[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that includes privacy-related activities affecting the system that require planning and coordination with {{ insert: param, pl-02_odp.01 }};",
"links": [
{
"href": "#pl-2_smt.a.14",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.14",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.15",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.15",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.a.15-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.15[01]",
"class": "sp800-53a"
}
],
"prose": "a security plan for the system is developed that is reviewed and approved by the authorizing official or designated representative prior to plan implementation;",
"links": [
{
"href": "#pl-2_smt.a.15",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.a.15-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02a.15[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy plan for the system is developed that is reviewed and approved by the authorizing official or designated representative prior to plan implementation.",
"links": [
{
"href": "#pl-2_smt.a.15",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a.15",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02b.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.b-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02b.[01]",
"class": "sp800-53a"
}
],
"prose": "copies of the plans are distributed to {{ insert: param, pl-02_odp.02 }};",
"links": [
{
"href": "#pl-2_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.b-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02b.[02]",
"class": "sp800-53a"
}
],
"prose": "subsequent changes to the plans are communicated to {{ insert: param, pl-02_odp.02 }};",
"links": [
{
"href": "#pl-2_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02c.",
"class": "sp800-53a"
}
],
"prose": "plans are reviewed {{ insert: param, pl-02_odp.03 }};",
"links": [
{
"href": "#pl-2_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02d.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.d-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02d.[01]",
"class": "sp800-53a"
}
],
"prose": "plans are updated to address changes to the system and environment of operations;",
"links": [
{
"href": "#pl-2_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.d-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02d.[02]",
"class": "sp800-53a"
}
],
"prose": "plans are updated to address problems identified during the plan implementation;",
"links": [
{
"href": "#pl-2_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.d-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02d.[03]",
"class": "sp800-53a"
}
],
"prose": "plans are updated to address problems identified during control assessments;",
"links": [
{
"href": "#pl-2_smt.d",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.d",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.e",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02e.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-2_obj.e-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02e.[01]",
"class": "sp800-53a"
}
],
"prose": "plans are protected from unauthorized disclosure;",
"links": [
{
"href": "#pl-2_smt.e",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_obj.e-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-02e.[02]",
"class": "sp800-53a"
}
],
"prose": "plans are protected from unauthorized modification.",
"links": [
{
"href": "#pl-2_smt.e",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt.e",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-02-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing system security and privacy plan development and implementation\n\nprocedures addressing security and privacy plan reviews and updates\n\nenterprise architecture documentation\n\nsystem security plan\n\nprivacy plan\n\nrecords of system security and privacy plan reviews and updates\n\nsecurity and privacy architecture and design documentation\n\nrisk assessments\n\nrisk assessment results\n\ncontrol assessment documentation\n\nother relevant documents or records"
}
]
},
{
"id": "pl-2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-02-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with system security and privacy planning and plan implementation responsibilities\n\nsystem developers\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-02-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for system security and privacy plan development, review, update, and approval\n\nmechanisms supporting the system security and privacy plan"
}
]
}
],
"controls": [
{
"id": "pl-2.1",
"class": "SP800-53-enhancement",
"title": "Concept of Operations",
"props": [
{
"name": "label",
"value": "PL-02(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-2(1)"
},
{
"name": "label",
"value": "PL-02(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-02.01"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#pl-7",
"rel": "incorporated-into"
}
]
},
{
"id": "pl-2.2",
"class": "SP800-53-enhancement",
"title": "Functional Architecture",
"props": [
{
"name": "label",
"value": "PL-02(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-2(2)"
},
{
"name": "label",
"value": "PL-02(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-02.02"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#pl-8",
"rel": "incorporated-into"
}
]
},
{
"id": "pl-2.3",
"class": "SP800-53-enhancement",
"title": "Plan and Coordinate with Other Organizational Entities",
"props": [
{
"name": "label",
"value": "PL-02(03)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-2(3)"
},
{
"name": "label",
"value": "PL-02(03)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-02.03"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#pl-2",
"rel": "incorporated-into"
}
]
}
]
},
{
"id": "pl-3",
"class": "SP800-53",
"title": "System Security Plan Update",
"props": [
{
"name": "label",
"value": "PL-03",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-3"
},
{
"name": "label",
"value": "PL-03",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-03"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#pl-2",
"rel": "incorporated-into"
}
]
},
{
"id": "pl-4",
"class": "SP800-53",
"title": "Rules of Behavior",
"params": [
{
"id": "pl-04_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pl-4_prm_1"
},
{
"name": "label",
"value": "PL-04_ODP[01]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "frequency for reviewing and updating the rules of behavior is defined;"
}
]
},
{
"id": "pl-04_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pl-4_prm_2"
},
{
"name": "label",
"value": "PL-04_ODP[02]",
"class": "sp800-53a"
}
],
"select": {
"how-many": "one-or-more",
"choice": [
"{{ insert: param, pl-04_odp.03 }} ",
"when the rules are revised or updated"
]
}
},
{
"id": "pl-04_odp.03",
"props": [
{
"name": "alt-identifier",
"value": "pl-4_prm_3"
},
{
"name": "label",
"value": "PL-04_ODP[03]",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "frequency for individuals to read and re-acknowledge the rules of behavior is defined (if selected);"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-04",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-4"
},
{
"name": "label",
"value": "PL-04",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-04"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#30eb758a-2707-4bca-90ad-949a74d4eb16",
"rel": "reference"
},
{
"href": "#ac-2",
"rel": "related"
},
{
"href": "#ac-6",
"rel": "related"
},
{
"href": "#ac-8",
"rel": "related"
},
{
"href": "#ac-9",
"rel": "related"
},
{
"href": "#ac-17",
"rel": "related"
},
{
"href": "#ac-18",
"rel": "related"
},
{
"href": "#ac-19",
"rel": "related"
},
{
"href": "#ac-20",
"rel": "related"
},
{
"href": "#at-2",
"rel": "related"
},
{
"href": "#at-3",
"rel": "related"
},
{
"href": "#cm-11",
"rel": "related"
},
{
"href": "#ia-2",
"rel": "related"
},
{
"href": "#ia-4",
"rel": "related"
},
{
"href": "#ia-5",
"rel": "related"
},
{
"href": "#mp-7",
"rel": "related"
},
{
"href": "#ps-6",
"rel": "related"
},
{
"href": "#ps-8",
"rel": "related"
},
{
"href": "#sa-5",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
}
],
"parts": [
{
"id": "pl-4_smt",
"name": "statement",
"parts": [
{
"id": "pl-4_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy;"
},
{
"id": "pl-4_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system;"
},
{
"id": "pl-4_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Review and update the rules of behavior {{ insert: param, pl-04_odp.01 }} ; and"
},
{
"id": "pl-4_smt.d",
"name": "item",
"props": [
{
"name": "label",
"value": "d."
}
],
"prose": "Require individuals who have acknowledged a previous version of the rules of behavior to read and re-acknowledge {{ insert: param, pl-04_odp.02 }}."
}
]
},
{
"id": "pl-4_gdn",
"name": "guidance",
"prose": "Rules of behavior represent a type of access agreement for organizational users. Other types of access agreements include nondisclosure agreements, conflict-of-interest agreements, and acceptable use agreements (see [PS-6](#ps-6) ). Organizations consider rules of behavior based on individual user roles and responsibilities and differentiate between rules that apply to privileged users and rules that apply to general users. Establishing rules of behavior for some types of non-organizational users, including individuals who receive information from federal systems, is often not feasible given the large number of such users and the limited nature of their interactions with the systems. Rules of behavior for organizational and non-organizational users can also be established in [AC-8](#ac-8) . The related controls section provides a list of controls that are relevant to organizational rules of behavior. [PL-4b](#pl-4_smt.b) , the documented acknowledgment portion of the control, may be satisfied by the literacy training and awareness and role-based training programs conducted by organizations if such training includes rules of behavior. Documented acknowledgements for rules of behavior include electronic or physical signatures and electronic agreement check boxes or radio buttons."
},
{
"id": "pl-4_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-4_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-4_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04a.[01]",
"class": "sp800-53a"
}
],
"prose": "rules that describe responsibilities and expected behavior for information and system usage, security, and privacy are established for individuals requiring access to the system;",
"links": [
{
"href": "#pl-4_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04a.[02]",
"class": "sp800-53a"
}
],
"prose": "rules that describe responsibilities and expected behavior for information and system usage, security, and privacy are provided to individuals requiring access to the system;",
"links": [
{
"href": "#pl-4_smt.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-4_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04b.",
"class": "sp800-53a"
}
],
"prose": "before authorizing access to information and the system, a documented acknowledgement from such individuals indicating that they have read, understand, and agree to abide by the rules of behavior is received;",
"links": [
{
"href": "#pl-4_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04c.",
"class": "sp800-53a"
}
],
"prose": "rules of behavior are reviewed and updated {{ insert: param, pl-04_odp.01 }};",
"links": [
{
"href": "#pl-4_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4_obj.d",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04d.",
"class": "sp800-53a"
}
],
"prose": "individuals who have acknowledged a previous version of the rules of behavior are required to read and reacknowledge {{ insert: param, pl-04_odp.02 }}.",
"links": [
{
"href": "#pl-4_smt.d",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-4_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-04-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing rules of behavior for system users\n\nrules of behavior\n\nsigned acknowledgements\n\nrecords for rules of behavior reviews and updates\n\nother relevant documents or records"
}
]
},
{
"id": "pl-4_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-04-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with responsibility for establishing, reviewing, and updating rules of behavior\n\norganizational personnel with responsibility for literacy training and awareness and role-based training\n\norganizational personnel who are authorized users of the system and have signed and resigned rules of behavior\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-4_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-04-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for establishing, reviewing, disseminating, and updating rules of behavior\n\nmechanisms supporting and/or implementing the establishment, review, dissemination, and update of rules of behavior"
}
]
}
],
"controls": [
{
"id": "pl-4.1",
"class": "SP800-53-enhancement",
"title": "Social Media and External Site/Application Usage Restrictions",
"props": [
{
"name": "label",
"value": "PL-04(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-4(1)"
},
{
"name": "label",
"value": "PL-04(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-04.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pl-4",
"rel": "required"
},
{
"href": "#ac-22",
"rel": "related"
},
{
"href": "#au-13",
"rel": "related"
}
],
"parts": [
{
"id": "pl-4.1_smt",
"name": "statement",
"prose": "Include in the rules of behavior, restrictions on:",
"parts": [
{
"id": "pl-4.1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Use of social media, social networking sites, and external sites/applications;"
},
{
"id": "pl-4.1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Posting organizational information on public websites; and"
},
{
"id": "pl-4.1_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "(c)"
}
],
"prose": "Use of organization-provided identifiers (e.g., email addresses) and authentication secrets (e.g., passwords) for creating accounts on external sites/applications."
}
]
},
{
"id": "pl-4.1_gdn",
"name": "guidance",
"prose": "Social media, social networking, and external site/application usage restrictions address rules of behavior related to the use of social media, social networking, and external sites when organizational personnel are using such sites for official duties or in the conduct of official business, when organizational information is involved in social media and social networking transactions, and when personnel access social media and networking sites from organizational systems. Organizations also address specific rules that prevent unauthorized entities from obtaining non-public organizational information from social media and networking sites either directly or through inference. Non-public information includes personally identifiable information and system account information."
},
{
"id": "pl-4.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04(01)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-4.1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04(01)(a)",
"class": "sp800-53a"
}
],
"prose": "the rules of behavior include restrictions on the use of social media, social networking sites, and external sites/applications;",
"links": [
{
"href": "#pl-4.1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4.1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04(01)(b)",
"class": "sp800-53a"
}
],
"prose": "the rules of behavior include restrictions on posting organizational information on public websites;",
"links": [
{
"href": "#pl-4.1_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4.1_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-04(01)(c)",
"class": "sp800-53a"
}
],
"prose": "the rules of behavior include restrictions on the use of organization-provided identifiers (e.g., email addresses) and authentication secrets (e.g., passwords) for creating accounts on external sites/applications.",
"links": [
{
"href": "#pl-4.1_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-4.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-4.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-04(01)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing rules of behavior for system users\n\nrules of behavior\n\ntraining policy\n\nother relevant documents or records"
}
]
},
{
"id": "pl-4.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-04(01)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with responsibility for establishing, reviewing, and updating rules of behavior\n\norganizational personnel with responsibility for literacy training and awareness and role-based training\n\norganizational personnel who are authorized users of the system and have signed rules of behavior\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-4.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-04(01)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for establishing rules of behavior\n\nmechanisms supporting and/or implementing the establishment of rules of behavior"
}
]
}
]
}
]
},
{
"id": "pl-5",
"class": "SP800-53",
"title": "Privacy Impact Assessment",
"props": [
{
"name": "label",
"value": "PL-05",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-5"
},
{
"name": "label",
"value": "PL-05",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-05"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#ra-8",
"rel": "incorporated-into"
}
]
},
{
"id": "pl-6",
"class": "SP800-53",
"title": "Security-related Activity Planning",
"props": [
{
"name": "label",
"value": "PL-06",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-6"
},
{
"name": "label",
"value": "PL-06",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-06"
},
{
"name": "status",
"value": "withdrawn"
}
],
"links": [
{
"href": "#pl-2",
"rel": "incorporated-into"
}
]
},
{
"id": "pl-7",
"class": "SP800-53",
"title": "Concept of Operations",
"params": [
{
"id": "pl-07_odp",
"props": [
{
"name": "alt-identifier",
"value": "pl-7_prm_1"
},
{
"name": "label",
"value": "PL-07_ODP",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "frequency for review and update of the Concept of Operations (CONOPS) is defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-07",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-7"
},
{
"name": "label",
"value": "PL-07",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-07"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#pl-2",
"rel": "related"
},
{
"href": "#sa-2",
"rel": "related"
},
{
"href": "#si-12",
"rel": "related"
}
],
"parts": [
{
"id": "pl-7_smt",
"name": "statement",
"parts": [
{
"id": "pl-7_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Develop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of information security and privacy; and"
},
{
"id": "pl-7_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Review and update the CONOPS {{ insert: param, pl-07_odp }}."
}
]
},
{
"id": "pl-7_gdn",
"name": "guidance",
"prose": "The CONOPS may be included in the security or privacy plans for the system or in other system development life cycle documents. The CONOPS is a living document that requires updating throughout the system development life cycle. For example, during system design reviews, the concept of operations is checked to ensure that it remains consistent with the design for controls, the system architecture, and the operational procedures. Changes to the CONOPS are reflected in ongoing updates to the security and privacy plans, security and privacy architectures, and other organizational documents, such as procurement specifications, system development life cycle documents, and systems engineering documents."
},
{
"id": "pl-7_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-07",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-7_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-07a.",
"class": "sp800-53a"
}
],
"prose": "a CONOPS for the system describing how the organization intends to operate the system from the perspective of information security and privacy is developed;",
"links": [
{
"href": "#pl-7_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-7_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-07b.",
"class": "sp800-53a"
}
],
"prose": "the CONOPS is reviewed and updated {{ insert: param, pl-07_odp }}.",
"links": [
{
"href": "#pl-7_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-7_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-7_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-07-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing security and privacy CONOPS development\n\nprocedures addressing security and privacy CONOPS reviews and updates\n\nsecurity and privacy CONOPS for the system\n\nsystem security plan\n\nprivacy plan\n\nrecords of security and privacy CONOPS reviews and updates\n\nother relevant documents or records"
}
]
},
{
"id": "pl-7_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-07-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-7_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-07-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for developing, reviewing, and updating the security CONOPS\n\nmechanisms supporting and/or implementing the development, review, and update of the security CONOPS"
}
]
}
]
},
{
"id": "pl-8",
"class": "SP800-53",
"title": "Security and Privacy Architectures",
"params": [
{
"id": "pl-08_odp",
"props": [
{
"name": "alt-identifier",
"value": "pl-8_prm_1"
},
{
"name": "label",
"value": "PL-08_ODP",
"class": "sp800-53a"
}
],
"label": "frequency",
"guidelines": [
{
"prose": "frequency for review and update to reflect changes in the enterprise architecture;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-08",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-8"
},
{
"name": "label",
"value": "PL-08",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-08"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#e3cc0520-a366-4fc9-abc2-5272db7e3564",
"rel": "reference"
},
{
"href": "#61ccf0f4-d3e7-42db-9796-ce6cb1c85989",
"rel": "reference"
},
{
"href": "#cm-2",
"rel": "related"
},
{
"href": "#cm-6",
"rel": "related"
},
{
"href": "#pl-2",
"rel": "related"
},
{
"href": "#pl-7",
"rel": "related"
},
{
"href": "#pl-9",
"rel": "related"
},
{
"href": "#pm-5",
"rel": "related"
},
{
"href": "#pm-7",
"rel": "related"
},
{
"href": "#ra-9",
"rel": "related"
},
{
"href": "#sa-3",
"rel": "related"
},
{
"href": "#sa-5",
"rel": "related"
},
{
"href": "#sa-8",
"rel": "related"
},
{
"href": "#sa-17",
"rel": "related"
},
{
"href": "#sc-7",
"rel": "related"
}
],
"parts": [
{
"id": "pl-8_smt",
"name": "statement",
"parts": [
{
"id": "pl-8_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "a."
}
],
"prose": "Develop security and privacy architectures for the system that:",
"parts": [
{
"id": "pl-8_smt.a.1",
"name": "item",
"props": [
{
"name": "label",
"value": "1."
}
],
"prose": "Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information;"
},
{
"id": "pl-8_smt.a.2",
"name": "item",
"props": [
{
"name": "label",
"value": "2."
}
],
"prose": "Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals;"
},
{
"id": "pl-8_smt.a.3",
"name": "item",
"props": [
{
"name": "label",
"value": "3."
}
],
"prose": "Describe how the architectures are integrated into and support the enterprise architecture; and"
},
{
"id": "pl-8_smt.a.4",
"name": "item",
"props": [
{
"name": "label",
"value": "4."
}
],
"prose": "Describe any assumptions about, and dependencies on, external systems and services;"
}
]
},
{
"id": "pl-8_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "b."
}
],
"prose": "Review and update the architectures {{ insert: param, pl-08_odp }} to reflect changes in the enterprise architecture; and"
},
{
"id": "pl-8_smt.c",
"name": "item",
"props": [
{
"name": "label",
"value": "c."
}
],
"prose": "Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions."
}
]
},
{
"id": "pl-8_gdn",
"name": "guidance",
"prose": "The security and privacy architectures at the system level are consistent with the organization-wide security and privacy architectures described in [PM-7](#pm-7) , which are integral to and developed as part of the enterprise architecture. The architectures include an architectural description, the allocation of security and privacy functionality (including controls), security- and privacy-related information for external interfaces, information being exchanged across the interfaces, and the protection mechanisms associated with each interface. The architectures can also include other information, such as user roles and the access privileges assigned to each role; security and privacy requirements; types of information processed, stored, and transmitted by the system; supply chain risk management requirements; restoration priorities of information and system services; and other protection needs.\n\n[SP 800-160-1](#e3cc0520-a366-4fc9-abc2-5272db7e3564) provides guidance on the use of security architectures as part of the system development life cycle process. [OMB M-19-03](#c5e11048-1d38-4af3-b00b-0d88dc26860c) requires the use of the systems security engineering concepts described in [SP 800-160-1](#e3cc0520-a366-4fc9-abc2-5272db7e3564) for high value assets. Security and privacy architectures are reviewed and updated throughout the system development life cycle, from analysis of alternatives through review of the proposed architecture in the RFP responses to the design reviews before and during implementation (e.g., during preliminary design reviews and critical design reviews).\n\nIn today\u2019s modern computing architectures, it is becoming less common for organizations to control all information resources. There may be key dependencies on external information services and service providers. Describing such dependencies in the security and privacy architectures is necessary for developing a comprehensive mission and business protection strategy. Establishing, developing, documenting, and maintaining under configuration control a baseline configuration for organizational systems is critical to implementing and maintaining effective architectures. The development of the architectures is coordinated with the senior agency information security officer and the senior agency official for privacy to ensure that the controls needed to support security and privacy requirements are identified and effectively implemented. In many circumstances, there may be no distinction between the security and privacy architecture for a system. In other circumstances, security objectives may be adequately satisfied, but privacy objectives may only be partially satisfied by the security requirements. In these cases, consideration of the privacy requirements needed to achieve satisfaction will result in a distinct privacy architecture. The documentation, however, may simply reflect the combined architectures.\n\n[PL-8](#pl-8) is primarily directed at organizations to ensure that architectures are developed for the system and, moreover, that the architectures are integrated with or tightly coupled to the enterprise architecture. In contrast, [SA-17](#sa-17) is primarily directed at the external information technology product and system developers and integrators. [SA-17](#sa-17) , which is complementary to [PL-8](#pl-8) , is selected when organizations outsource the development of systems or components to external entities and when there is a need to demonstrate consistency with the organization\u2019s enterprise architecture and security and privacy architectures."
},
{
"id": "pl-8_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8_obj.a.1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.01",
"class": "sp800-53a"
}
],
"prose": "a security architecture for the system describes the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information;",
"links": [
{
"href": "#pl-8_smt.a.1",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.a.2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.02",
"class": "sp800-53a"
}
],
"prose": "a privacy architecture describes the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals;",
"links": [
{
"href": "#pl-8_smt.a.2",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.a.3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.03",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8_obj.a.3-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.03[01]",
"class": "sp800-53a"
}
],
"prose": "a security architecture for the system describes how the architecture is integrated into and supports the enterprise architecture;",
"links": [
{
"href": "#pl-8_smt.a.3",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.a.3-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.03[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy architecture for the system describes how the architecture is integrated into and supports the enterprise architecture;",
"links": [
{
"href": "#pl-8_smt.a.3",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8_smt.a.3",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.a.4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.04",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8_obj.a.4-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.04[01]",
"class": "sp800-53a"
}
],
"prose": "a security architecture for the system describes any assumptions about and dependencies on external systems and services;",
"links": [
{
"href": "#pl-8_smt.a.4",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.a.4-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08a.04[02]",
"class": "sp800-53a"
}
],
"prose": "a privacy architecture for the system describes any assumptions about and dependencies on external systems and services;",
"links": [
{
"href": "#pl-8_smt.a.4",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8_smt.a.4",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08b.",
"class": "sp800-53a"
}
],
"prose": "changes in the enterprise architecture are reviewed and updated {{ insert: param, pl-08_odp }} to reflect changes in the enterprise architecture;",
"links": [
{
"href": "#pl-8_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.c",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8_obj.c-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.[01]",
"class": "sp800-53a"
}
],
"prose": "planned architecture changes are reflected in the security plan;",
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.c-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.[02]",
"class": "sp800-53a"
}
],
"prose": "planned architecture changes are reflected in the privacy plan;",
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.c-3",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.[03]",
"class": "sp800-53a"
}
],
"prose": "planned architecture changes are reflected in the Concept of Operations (CONOPS);",
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.c-4",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.[04]",
"class": "sp800-53a"
}
],
"prose": "planned architecture changes are reflected in criticality analysis;",
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.c-5",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.[05]",
"class": "sp800-53a"
}
],
"prose": "planned architecture changes are reflected in organizational procedures;",
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_obj.c-6",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08c.[06]",
"class": "sp800-53a"
}
],
"prose": "planned architecture changes are reflected in procurements and acquisitions.",
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8_smt.c",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-08-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing information security and privacy architecture development\n\nprocedures addressing information security and privacy architecture reviews and updates\n\nenterprise architecture documentation\n\ninformation security and privacy architecture documentation\n\nsystem security plan\n\nprivacy plan\n\nsecurity and privacy CONOPS for the system\n\nrecords of information security and privacy architecture reviews and updates\n\nother relevant documents or records"
}
]
},
{
"id": "pl-8_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-08-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with information security and privacy architecture development responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-8_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-08-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for developing, reviewing, and updating the information security and privacy architecture\n\nmechanisms supporting and/or implementing the development, review, and update of the information security and privacy architecture"
}
]
}
],
"controls": [
{
"id": "pl-8.1",
"class": "SP800-53-enhancement",
"title": "Defense in Depth",
"params": [
{
"id": "pl-08.01_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pl-8.1_prm_1"
},
{
"name": "label",
"value": "PL-08(01)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "controls",
"guidelines": [
{
"prose": "controls to be allocated are defined;"
}
]
},
{
"id": "pl-08.01_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pl-8.1_prm_2"
},
{
"name": "label",
"value": "PL-08(01)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "locations and architectural layers",
"guidelines": [
{
"prose": "locations and architectural layers are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-08(01)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-8(1)"
},
{
"name": "label",
"value": "PL-08(01)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-08.01"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pl-8",
"rel": "required"
},
{
"href": "#sc-2",
"rel": "related"
},
{
"href": "#sc-3",
"rel": "related"
},
{
"href": "#sc-29",
"rel": "related"
},
{
"href": "#sc-36",
"rel": "related"
}
],
"parts": [
{
"id": "pl-8.1_smt",
"name": "statement",
"prose": "Design the security and privacy architectures for the system using a defense-in-depth approach that:",
"parts": [
{
"id": "pl-8.1_smt.a",
"name": "item",
"props": [
{
"name": "label",
"value": "(a)"
}
],
"prose": "Allocates {{ insert: param, pl-08.01_odp.01 }} to {{ insert: param, pl-08.01_odp.02 }} ; and"
},
{
"id": "pl-8.1_smt.b",
"name": "item",
"props": [
{
"name": "label",
"value": "(b)"
}
],
"prose": "Ensures that the allocated controls operate in a coordinated and mutually reinforcing manner."
}
]
},
{
"id": "pl-8.1_gdn",
"name": "guidance",
"prose": "Organizations strategically allocate security and privacy controls in the security and privacy architectures so that adversaries must overcome multiple controls to achieve their objective. Requiring adversaries to defeat multiple controls makes it more difficult to attack information resources by increasing the work factor of the adversary; it also increases the likelihood of detection. The coordination of allocated controls is essential to ensure that an attack that involves one control does not create adverse, unintended consequences by interfering with other controls. Unintended consequences can include system lockout and cascading alarms. The placement of controls in systems and organizations is an important activity that requires thoughtful analysis. The value of organizational assets is an important consideration in providing additional layering. Defense-in-depth architectural approaches include modularity and layering (see [SA-8(3)](#sa-8.3) ), separation of system and user functionality (see [SC-2](#sc-2) ), and security function isolation (see [SC-3](#sc-3))."
},
{
"id": "pl-8.1_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8.1_obj.a",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)(a)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8.1_obj.a-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)(a)[01]",
"class": "sp800-53a"
}
],
"prose": "the security architecture for the system is designed using a defense-in-depth approach that allocates {{ insert: param, pl-08.01_odp.01 }} to {{ insert: param, pl-08.01_odp.02 }};",
"links": [
{
"href": "#pl-8.1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8.1_obj.a-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)(a)[02]",
"class": "sp800-53a"
}
],
"prose": "the privacy architecture for the system is designed using a defense-in-depth approach that allocates {{ insert: param, pl-08.01_odp.01 }} to {{ insert: param, pl-08.01_odp.02 }};",
"links": [
{
"href": "#pl-8.1_smt.a",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8.1_smt.a",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8.1_obj.b",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)(b)",
"class": "sp800-53a"
}
],
"parts": [
{
"id": "pl-8.1_obj.b-1",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)(b)[01]",
"class": "sp800-53a"
}
],
"prose": "the security architecture for the system is designed using a defense-in-depth approach that ensures the allocated controls operate in a coordinated and mutually reinforcing manner;",
"links": [
{
"href": "#pl-8.1_smt.b",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8.1_obj.b-2",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(01)(b)[02]",
"class": "sp800-53a"
}
],
"prose": "the privacy architecture for the system is designed using a defense-in-depth approach that ensures the allocated controls operate in a coordinated and mutually reinforcing manner.",
"links": [
{
"href": "#pl-8.1_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8.1_smt.b",
"rel": "assessment-for"
}
]
}
],
"links": [
{
"href": "#pl-8.1_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8.1_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-08-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing information security and privacy architecture development\n\nenterprise architecture documentation\n\ninformation security and privacy architecture documentation\n\nsystem security plan\n\nprivacy plan\n\nsecurity and privacy CONOPS for the system\n\nother relevant documents or records"
}
]
},
{
"id": "pl-8.1_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-08-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with information security and privacy architecture development responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-8.1_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-08-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for designing the information security and privacy architecture\n\nmechanisms supporting and/or implementing the design of the information security and privacy architecture"
}
]
}
]
},
{
"id": "pl-8.2",
"class": "SP800-53-enhancement",
"title": "Supplier Diversity",
"params": [
{
"id": "pl-08.02_odp.01",
"props": [
{
"name": "alt-identifier",
"value": "pl-8.2_prm_1"
},
{
"name": "label",
"value": "PL-08(02)_ODP[01]",
"class": "sp800-53a"
}
],
"label": "controls",
"guidelines": [
{
"prose": "controls to be allocated are defined;"
}
]
},
{
"id": "pl-08.02_odp.02",
"props": [
{
"name": "alt-identifier",
"value": "pl-8.2_prm_2"
},
{
"name": "label",
"value": "PL-08(02)_ODP[02]",
"class": "sp800-53a"
}
],
"label": "locations and architectural layers",
"guidelines": [
{
"prose": "locations and architectural layers are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-08(02)",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-8(2)"
},
{
"name": "label",
"value": "PL-08(02)",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-08.02"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#pl-8",
"rel": "required"
},
{
"href": "#sc-29",
"rel": "related"
},
{
"href": "#sr-3",
"rel": "related"
}
],
"parts": [
{
"id": "pl-8.2_smt",
"name": "statement",
"prose": "Require that {{ insert: param, pl-08.02_odp.01 }} allocated to {{ insert: param, pl-08.02_odp.02 }} are obtained from different suppliers."
},
{
"id": "pl-8.2_gdn",
"name": "guidance",
"prose": "Information technology products have different strengths and weaknesses. Providing a broad spectrum of products complements the individual offerings. For example, vendors offering malicious code protection typically update their products at different times, often developing solutions for known viruses, Trojans, or worms based on their priorities and development schedules. By deploying different products at different locations, there is an increased likelihood that at least one of the products will detect the malicious code. With respect to privacy, vendors may offer products that track personally identifiable information in systems. Products may use different tracking methods. Using multiple products may result in more assurance that personally identifiable information is inventoried."
},
{
"id": "pl-8.2_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-08(02)",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, pl-08.02_odp.01 }} that are allocated to {{ insert: param, pl-08.02_odp.02 }} are required to be obtained from different suppliers.",
"links": [
{
"href": "#pl-8.2_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-8.2_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-08(02)-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing information security and privacy architecture development\n\nenterprise architecture documentation\n\ninformation security and privacy architecture documentation\n\nsystem security plan\n\nprivacy plan\n\nsecurity and privacy CONOPS for the system\n\nIT acquisitions policy\n\nother relevant documents or records"
}
]
},
{
"id": "pl-8.2_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-08(02)-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with information security and privacy architecture development responsibilities\n\norganizational personnel with acquisition responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-8.2_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-08(02)-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for obtaining information security and privacy safeguards from different suppliers"
}
]
}
]
}
]
},
{
"id": "pl-9",
"class": "SP800-53",
"title": "Central Management",
"params": [
{
"id": "pl-09_odp",
"props": [
{
"name": "alt-identifier",
"value": "pl-9_prm_1"
},
{
"name": "label",
"value": "PL-09_ODP",
"class": "sp800-53a"
}
],
"label": "controls and related processes",
"guidelines": [
{
"prose": "security and privacy controls and related processes to be centrally managed are defined;"
}
]
}
],
"props": [
{
"name": "label",
"value": "PL-09",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-9"
},
{
"name": "label",
"value": "PL-09",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-09"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
},
{
"name": "contributes-to-assurance",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "true"
}
],
"links": [
{
"href": "#27847491-5ce1-4f6a-a1e4-9e483782f0ef",
"rel": "reference"
},
{
"href": "#482e4c99-9dc4-41ad-bba8-0f3f0032c1f8",
"rel": "reference"
},
{
"href": "#pl-8",
"rel": "related"
},
{
"href": "#pm-9",
"rel": "related"
}
],
"parts": [
{
"id": "pl-9_smt",
"name": "statement",
"prose": "Centrally manage {{ insert: param, pl-09_odp }}."
},
{
"id": "pl-9_gdn",
"name": "guidance",
"prose": "Central management refers to organization-wide management and implementation of selected controls and processes. This includes planning, implementing, assessing, authorizing, and monitoring the organization-defined, centrally managed controls and processes. As the central management of controls is generally associated with the concept of common (inherited) controls, such management promotes and facilitates standardization of control implementations and management and the judicious use of organizational resources. Centrally managed controls and processes may also meet independence requirements for assessments in support of initial and ongoing authorizations to operate and as part of organizational continuous monitoring.\n\nAutomated tools (e.g., security information and event management tools or enterprise security monitoring and management tools) can improve the accuracy, consistency, and availability of information associated with centrally managed controls and processes. Automation can also provide data aggregation and data correlation capabilities; alerting mechanisms; and dashboards to support risk-based decision-making within the organization.\n\nAs part of the control selection processes, organizations determine the controls that may be suitable for central management based on resources and capabilities. It is not always possible to centrally manage every aspect of a control. In such cases, the control can be treated as a hybrid control with the control managed and implemented centrally or at the system level. The controls and control enhancements that are candidates for full or partial central management include but are not limited to: [AC-2(1)](#ac-2.1), [AC-2(2)](#ac-2.2), [AC-2(3)](#ac-2.3), [AC-2(4)](#ac-2.4), [AC-4(all)](#ac-4), [AC-17(1)](#ac-17.1), [AC-17(2)](#ac-17.2), [AC-17(3)](#ac-17.3), [AC-17(9)](#ac-17.9), [AC-18(1)](#ac-18.1), [AC-18(3)](#ac-18.3), [AC-18(4)](#ac-18.4), [AC-18(5)](#ac-18.5), [AC-19(4)](#ac-19.4), [AC-22](#ac-22), [AC-23](#ac-23), [AT-2(1)](#at-2.1), [AT-2(2)](#at-2.2), [AT-3(1)](#at-3.1), [AT-3(2)](#at-3.2), [AT-3(3)](#at-3.3), [AT-4](#at-4), [AU-3](#au-3), [AU-6(1)](#au-6.1), [AU-6(3)](#au-6.3), [AU-6(5)](#au-6.5), [AU-6(6)](#au-6.6), [AU-6(9)](#au-6.9), [AU-7(1)](#au-7.1), [AU-7(2)](#au-7.2), [AU-11](#au-11), [AU-13](#au-13), [AU-16](#au-16), [CA-2(1)](#ca-2.1), [CA-2(2)](#ca-2.2), [CA-2(3)](#ca-2.3), [CA-3(1)](#ca-3.1), [CA-3(2)](#ca-3.2), [CA-3(3)](#ca-3.3), [CA-7(1)](#ca-7.1), [CA-9](#ca-9), [CM-2(2)](#cm-2.2), [CM-3(1)](#cm-3.1), [CM-3(4)](#cm-3.4), [CM-4](#cm-4), [CM-6](#cm-6), [CM-6(1)](#cm-6.1), [CM-7(2)](#cm-7.2), [CM-7(4)](#cm-7.4), [CM-7(5)](#cm-7.5), [CM-8(all)](#cm-8), [CM-9(1)](#cm-9.1), [CM-10](#cm-10), [CM-11](#cm-11), [CP-7(all)](#cp-7), [CP-8(all)](#cp-8), [SC-43](#sc-43), [SI-2](#si-2), [SI-3](#si-3), [SI-4(all)](#si-4), [SI-7](#si-7), [SI-8](#si-8)."
},
{
"id": "pl-9_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-09",
"class": "sp800-53a"
}
],
"prose": "{{ insert: param, pl-09_odp }} are centrally managed.",
"links": [
{
"href": "#pl-9_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-9_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-09-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing security and privacy plan development and implementation\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pl-9_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-09-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with responsibilities for planning/implementing central management of controls and related processes\n\norganizational personnel with information security and privacy responsibilities"
}
]
},
{
"id": "pl-9_asm-test",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "TEST"
},
{
"name": "label",
"value": "PL-09-Test",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational processes for the central management of controls and related processes\n\nmechanisms supporting and/or implementing central management of controls and related processes"
}
]
}
]
},
{
"id": "pl-10",
"class": "SP800-53",
"title": "Baseline Selection",
"props": [
{
"name": "label",
"value": "PL-10",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-10"
},
{
"name": "label",
"value": "PL-10",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-10"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#628d22a1-6a11-4784-bc59-5cd9497b5445",
"rel": "reference"
},
{
"href": "#599fb53d-5041-444e-a7fe-640d6d30ad05",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#482e4c99-9dc4-41ad-bba8-0f3f0032c1f8",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#46d9e201-840e-440e-987c-2c773333c752",
"rel": "reference"
},
{
"href": "#e72fde0b-6fc2-497e-a9db-d8fce5a11b8a",
"rel": "reference"
},
{
"href": "#9be5d661-421f-41ad-854e-86f98b811891",
"rel": "reference"
},
{
"href": "#e3cc0520-a366-4fc9-abc2-5272db7e3564",
"rel": "reference"
},
{
"href": "#4e4fbc93-333d-45e6-a875-de36b878b6b9",
"rel": "reference"
},
{
"href": "#pl-2",
"rel": "related"
},
{
"href": "#pl-11",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#sa-8",
"rel": "related"
}
],
"parts": [
{
"id": "pl-10_smt",
"name": "statement",
"prose": "Select a control baseline for the system."
},
{
"id": "pl-10_gdn",
"name": "guidance",
"prose": "Control baselines are predefined sets of controls specifically assembled to address the protection needs of a group, organization, or community of interest. Controls are chosen for baselines to either satisfy mandates imposed by laws, executive orders, directives, regulations, policies, standards, and guidelines or address threats common to all users of the baseline under the assumptions specific to the baseline. Baselines represent a starting point for the protection of individuals\u2019 privacy, information, and information systems with subsequent tailoring actions to manage risk in accordance with mission, business, or other constraints (see [PL-11](#pl-11) ). Federal control baselines are provided in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) . The selection of a control baseline is determined by the needs of stakeholders. Stakeholder needs consider mission and business requirements as well as mandates imposed by applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. For example, the control baselines in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) are based on the requirements from [FISMA](#0c67b2a9-bede-43d2-b86d-5f35b8be36e9) and [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) . The requirements, along with the NIST standards and guidelines implementing the legislation, direct organizations to select one of the control baselines after the reviewing the information types and the information that is processed, stored, and transmitted on the system; analyzing the potential adverse impact of the loss or compromise of the information or system on the organization\u2019s operations and assets, individuals, other organizations, or the Nation; and considering the results from system and organizational risk assessments. [CNSSI 1253](#4e4fbc93-333d-45e6-a875-de36b878b6b9) provides guidance on control baselines for national security systems."
},
{
"id": "pl-10_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-10",
"class": "sp800-53a"
}
],
"prose": "a control baseline for the system is selected.",
"links": [
{
"href": "#pl-10_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-10_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-10-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing system security and privacy plan development and implementation\n\nprocedures addressing system security and privacy plan reviews and updates\n\nsystem design documentation\n\nsystem architecture and configuration documentation\n\nsystem categorization decision\n\ninformation types stored, transmitted, and processed by the system\n\nsystem element/component information\n\nstakeholder needs analysis\n\nlist of security and privacy requirements allocated to the system, system elements, and environment of operation\n\nlist of contractual requirements allocated to external providers of the system or system element\n\nbusiness impact analysis or criticality analysis\n\nrisk assessments\n\nrisk management strategy\n\norganizational security and privacy policy\n\nfederal or organization-approved or mandated baselines or overlays\n\nsystem security plan\n\nprivacy plan\n\nother relevant documents or records"
}
]
},
{
"id": "pl-10_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-10-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with information security and privacy responsibilities\n\norganizational personnel with responsibility for organizational risk management activities"
}
]
}
]
},
{
"id": "pl-11",
"class": "SP800-53",
"title": "Baseline Tailoring",
"props": [
{
"name": "label",
"value": "PL-11",
"class": "zero-padded"
},
{
"name": "label",
"value": "PL-11"
},
{
"name": "label",
"value": "PL-11",
"class": "sp800-53a"
},
{
"name": "sort-id",
"value": "pl-11"
},
{
"name": "implementation-level",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "organization"
}
],
"links": [
{
"href": "#628d22a1-6a11-4784-bc59-5cd9497b5445",
"rel": "reference"
},
{
"href": "#599fb53d-5041-444e-a7fe-640d6d30ad05",
"rel": "reference"
},
{
"href": "#08b07465-dbdc-48d6-8a0b-37279602ac16",
"rel": "reference"
},
{
"href": "#482e4c99-9dc4-41ad-bba8-0f3f0032c1f8",
"rel": "reference"
},
{
"href": "#cec037f3-8aba-4c97-84b4-4082f9e515d2",
"rel": "reference"
},
{
"href": "#46d9e201-840e-440e-987c-2c773333c752",
"rel": "reference"
},
{
"href": "#e72fde0b-6fc2-497e-a9db-d8fce5a11b8a",
"rel": "reference"
},
{
"href": "#9be5d661-421f-41ad-854e-86f98b811891",
"rel": "reference"
},
{
"href": "#e3cc0520-a366-4fc9-abc2-5272db7e3564",
"rel": "reference"
},
{
"href": "#4e4fbc93-333d-45e6-a875-de36b878b6b9",
"rel": "reference"
},
{
"href": "#pl-10",
"rel": "related"
},
{
"href": "#ra-2",
"rel": "related"
},
{
"href": "#ra-3",
"rel": "related"
},
{
"href": "#ra-9",
"rel": "related"
},
{
"href": "#sa-8",
"rel": "related"
}
],
"parts": [
{
"id": "pl-11_smt",
"name": "statement",
"prose": "Tailor the selected control baseline by applying specified tailoring actions."
},
{
"id": "pl-11_gdn",
"name": "guidance",
"prose": "The concept of tailoring allows organizations to specialize or customize a set of baseline controls by applying a defined set of tailoring actions. Tailoring actions facilitate such specialization and customization by allowing organizations to develop security and privacy plans that reflect their specific mission and business functions, the environments where their systems operate, the threats and vulnerabilities that can affect their systems, and any other conditions or situations that can impact their mission or business success. Tailoring guidance is provided in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) . Tailoring a control baseline is accomplished by identifying and designating common controls, applying scoping considerations, selecting compensating controls, assigning values to control parameters, supplementing the control baseline with additional controls as needed, and providing information for control implementation. The general tailoring actions in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) can be supplemented with additional actions based on the needs of organizations. Tailoring actions can be applied to the baselines in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) in accordance with the security and privacy requirements from [FISMA](#0c67b2a9-bede-43d2-b86d-5f35b8be36e9), [PRIVACT](#18e71fec-c6fd-475a-925a-5d8495cf8455) , and [OMB A-130](#27847491-5ce1-4f6a-a1e4-9e483782f0ef) . Alternatively, other communities of interest adopting different control baselines can apply the tailoring actions in [SP 800-53B](#46d9e201-840e-440e-987c-2c773333c752) to specialize or customize the controls that represent the specific needs and concerns of those entities."
},
{
"id": "pl-11_obj",
"name": "assessment-objective",
"props": [
{
"name": "label",
"value": "PL-11",
"class": "sp800-53a"
}
],
"prose": "the selected control baseline is tailored by applying specified tailoring actions.",
"links": [
{
"href": "#pl-11_smt",
"rel": "assessment-for"
}
]
},
{
"id": "pl-11_asm-examine",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "EXAMINE"
},
{
"name": "label",
"value": "PL-11-Examine",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Security and privacy planning policy\n\nprocedures addressing system security and privacy plan development and implementation\n\nsystem design documentation\n\nsystem categorization decision\n\ninformation types stored, transmitted, and processed by the system\n\nsystem element/component information\n\nstakeholder needs analysis\n\nlist of security and privacy requirements allocated to the system, system elements, and environment of operation\n\nlist of contractual requirements allocated to external providers of the system or system element\n\nbusiness impact analysis or criticality analysis\n\nrisk assessments\n\nrisk management strategy\n\norganizational security and privacy policy\n\nfederal or organization-approved or mandated baselines or overlays\n\nbaseline tailoring rationale\n\nsystem security plan\n\nprivacy plan\n\nrecords of system security and privacy plan reviews and updates\n\nother relevant documents or records"
}
]
},
{
"id": "pl-11_asm-interview",
"name": "assessment-method",
"props": [
{
"name": "method",
"ns": "http://csrc.nist.gov/ns/rmf",
"value": "INTERVIEW"
},
{
"name": "label",
"value": "PL-11-Interview",
"class": "sp800-53a"
}
],
"parts": [
{
"name": "assessment-objects",
"prose": "Organizational personnel with security and privacy planning and plan implementation responsibilities\n\norganizational personnel with information security and privacy responsibilities"
}
]
}
]
}
]
}
}