# PL-06 Security-related Activity Planning

NIST SP 800-53 control. Family: PL Planning. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into PL-02.

Statement: The organization plans and coordinates security-related activities affecting the information system before conducting such activities in order to reduce the impact on organizational operations (i.e., mission, functions, image, and reputation), organizational assets, and individuals.
Guidance: Routine security-related activities include, but are not limited to, security assessments, audits, system hardware and software maintenance, security certifications, and testing/exercises. Organizational advance planning and coordination includes both emergency and non-emergency (i.e., routine) situations.

## Clauses by framework (7 frameworks)
- iso_42001_2023: A.6.1.2
- anssi: Hygiene.36, SecNumCloud.6.2
- osfi_b13: B-13.1.2
- finma_circular: IV.A(23), IV.A(24), IV.B.a(48)
- gdpr: Art.25(1), Art.35(1)
- dora: Art.6(1)
- fisc: FISC.T1

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PL-06
- Clauses only: /api/v1/controls/PL-06?fields=mappings
- Page for people: /controls/pl-06/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
