πΌ PM-1 Information Security Program Plan
- Contextual name: πΌ PM-1 Information Security Program Plan
- ID:
/frameworks/nist-sp-800-53-r5/pm/01
- Located in: πΌ PM Program Management
Descriptionβ
a. Develop and disseminate an organization-wide information security program plan that:
- Provides an overview of the requirements for the security program and a description of the security program management controls and common controls in place or planned for meeting those requirements;
- Includes the identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance;
- Reflects the coordination among organizational entities responsible for information security; and
- Is approved by a senior official with responsibility and accountability for the risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation; b. Review and update the organization-wide information security program plan [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and c. Protect the information security program plan from unauthorized disclosure and modification.
Similarβ
- Internal
- ID:
dec-c-c615c7cc
- ID:
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|