# PL-03 System Security Plan Update

NIST SP 800-53 control. Family: PL Planning. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into PL-02.

Statement: The organization reviews the security plan for the information system [Assignment: organization-defined frequency, at least annually] and revises the plan to address system/organizational changes or problems identified during plan implementation or security control assessments.
Guidance: Significant changes are defined in advance by the organization and identified in the configuration management process. NIST Special Publication 800-18 provides guidance on security plan updates.

## Clauses by framework (10 frameworks)
- iso_42001_2023: A.2.4
- anssi: Hygiene.36, SecNumCloud.6.2
- osfi_b13: B-13.1.2, B-13.1.3
- finma_circular: IV.A(23), IV.A(25)
- gdpr: Art.25(1)
- dora: Art.6(4)
- ffiec_is: II.C.1
- iosco_cyber: LE-2
- nydfs_500: 500.3
- naic_ds: 4E

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PL-03
- Clauses only: /api/v1/controls/PL-03?fields=mappings
- Page for people: /controls/pl-03/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
