PL-06 Security-related Activity Planning
Planning
Withdrawn
NIST has withdrawn this control from SP 800-53. Its content moved into PL-02. The description below is the one it had before.
Description
The organization plans and coordinates security-related activities affecting the information system before conducting such activities in order to reduce the impact on organizational operations (i.e., mission, functions, image, and reputation), organizational assets, and individuals.
Supplemental Guidance
Routine security-related activities include, but are not limited to, security assessments, audits, system hardware and software maintenance, security certifications, and testing/exercises. Organizational advance planning and coordination includes both emergency and non-emergency (i.e., routine) situations.
Compliance Mappings
ISO 42001:2023
A.6.1.2
ANSSI
Hygiene.36SecNumCloud.6.2
FINMA Circular 2023/1
IV.A(23)IV.A(24)IV.B.a(48)
OSFI B-13
B-13.1.2
EU GDPR
Art.25(1)Art.35(1)
EU DORA
Art.6(1)
FISC Security Guidelines
FISC.T1
ISO 17799 (legacy)
15.3.1
COBIT 4.1 (legacy)
None.