# PL-09 Central Management

NIST SP 800-53 control. Family: PL Planning. Function: preventative. Baselines: privacy. Mapping licence: CC BY-SA 4.0.

Statement: Centrally manage [Assignment: organization-defined controls and related processes].
Guidance: Central management refers to organization-wide management and implementation of selected controls and processes. This includes planning, implementing, assessing, authorizing, and monitoring the organization-defined, centrally managed controls and processes. As the central management of controls is generally associated with the concept of common (inherited) controls, such management promotes and facilitates standardization of control implementations and management and the judicious use of organizational resources. Centrally managed controls and processes may also meet independence requirements for assessments in support of initial and ongoing authorizations to operate and as part of organizational continuous monitoring. Automated tools (e.g., security information and event management tools or enterprise security monitoring and management tools) can improve the accuracy, consistency, and availability of information associated with centrally managed controls and processes. Automation can also provide data aggregation and data correlation capabilities; alerting mechanisms; and dashboards to support risk-based decision-making within the organization. As part of the control selection processes, organizations determine the controls that may be suitable for central management based on resources and capabilities. It is not always possible to centrally manage every aspect of a control. In such cases, the control can be treated as a hybrid control with the control managed and implemented centrally or at the system level. The controls and control enhancements that are candidates for full or partial central management include but are not limited to: AC-02(01), AC-02(02), AC-02(03), AC-02(04), AC-04(all), AC-17(01), AC-17(02), AC-17(03), AC-17(09), AC-18(01), AC-18(03), AC-18(04), AC-18(05), AC-19(04), AC-22, AC-23, AT-02(01), AT-02(02), AT-03(01), AT-03(02), AT-03(03), AT-04, AU-03, AU-06(01), AU-06(03), AU-06(05), AU-06(06), AU-06(09), AU-07(01), AU-07(02), AU-11, AU-13, AU-16, CA-02(01), CA-02(02), CA-02(03), CA-03(01), CA-03(02), CA-03(03), CA-07(01), CA-9, CM-02(02), CM-03(01), CM-03(04), CM-04, CM-06, CM-06(01), CM-07(02), CM-07(04), CM-07(05), CM-8(all), CM-09(01), CM-10, CM-11, CP-07(all), CP-08(all), SC-43, SI-02, SI-03, SI-04(all), SI-07, SI-08.

## Patterns that use it (1)
- Important (1): SP-018 Information Security Management System

## Clauses by framework (46 frameworks)
- iso_27001_2022: 4.4, 8.1. OSA's own, not in NIST's crosswalk: 4.4, 8.1
- cobit_2019: APO01, APO13, EDM01
- pci_dss_v4: 12.1
- nist_csf_2: DE.AE-03, PR.PS-01. OSA's own, not in NIST's crosswalk: DE.AE-03, PR.PS-01
- soc2_tsc: CC1.1, CC5.3
- iso_42001_2023: A.2.2
- iec_62443: 2-1 4.2
- nis2: Art. 21(2)(a)
- apra_cps_234: Para 15
- mas_trm: 4
- bsi_grundschutz: ISMS.1, ORP.1
- anssi: Hygiene.36, RGS.1.3
- osfi_b13: B-13.1.2, B-13.1.3
- finma_circular: IV.A(23), IV.A(24), IV.A(31)
- gdpr: Art.24(1), Art.24(2)
- dora: Art.5(1), Art.5(2), Art.6(1)
- rbi_csf: ITGRCA.4
- fisc: FISC.O1, FISC.T1
- lgpd_bcb: BCB.Art.2, BCB.Art.17, LGPD.Art.50, LGPD.BCB.Integration
- hkma_tme1: TME1.2.1, TME1.2.3, TME1.2.4, TME1.7.1
- cbb_tm: TM-1, TM-2, TM-3, TM-4
- cbuae: CR-1
- nca_ecc: 1-1, 1-2
- qatar_nia: GV
- sama_csf: 1.1, 1.3, 1.8
- uae_ia: T1
- bog_cisd: CISD-II
- bom_ctrm: 1.1, 1.4
- cbe_csf: GOV-1
- cbn_csf: Part1.1, Part1.3
- sa_js2: JS2-4, JS2-5
- bcbs_239: Principle 1
- bot_cyber: Ch1.2
- cpmi_pfmi: CG.GOV, PFMI.P2, PFMI.P3
- eba_ict: 3.2.1, 3.2.2, 3.3.1
- ecb_croe: CROE.2.1.1
- ffiec_is: II.C.2
- iosco_cyber: GOV-1, GOV-2, PFMI-2, PFMI-3
- sebi_cscrf: GV.RM
- common_criteria: CC Part 2 — FMT
- fca_sysc_13: SYSC 13.1-2, SYSC 13.G.1
- hitrust_csf: 05.a
- lloyds_ms: CRM.1, GOV.1, MS8.1
- naic_ds: 4B
- nhs_dspt: NDG-9.1
- solvency_ii: Art.41(1), Art.44(1), DR.258, EIOPA-ICT-4.1, EIOPA-ICT-4.2
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PL-09
- Clauses only: /api/v1/controls/PL-09?fields=mappings
- Page for people: /controls/pl-09/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
