The organisation develops security and privacy plans for the system that align with the enterprise architecture, define components, describe the operational and business context, identify role holders, identify information types, give the security categorization with rationale, describe specific threats, give privacy risk assessment results for systems handling personal information, describe the operating environment and dependencies, summarise security and privacy requirements, identify baselines or overlays, describe the controls in place or planned with tailoring rationale, include risk determinations for architecture and design decisions, identify activities needing coordination with defined groups, and are approved by the authorizing official before implementation. Canada-specific additions (items 400 and 401): the plans record the business purposes for processing personal information and define retention and disposition standards for it. The plans are distributed and changes communicated to defined roles, reviewed at a set frequency, updated for system and environment changes and assessment findings, and protected from unauthorized disclosure and modification. 3 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.