Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
PL: Planning – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue PL-02: PL-02 System security and privacy plans

The organisation develops security and privacy plans for the system that align with the enterprise architecture, define components, describe the operational and business context, identify role holders, identify information types, give the security categorization with rationale, describe specific threats, give privacy risk assessment results for systems handling personal information, describe the operating environment and dependencies, summarise security and privacy requirements, identify baselines or overlays, describe the controls in place or planned with tailoring rationale, include risk determinations for architecture and design decisions, identify activities needing coordination with defined groups, and are approved by the authorizing official before implementation. Canada-specific additions (items 400 and 401): the plans record the business purposes for processing personal information and define retention and disposition standards for it. The plans are distributed and changes communicated to defined roles, reviewed at a set frequency, updated for system and environment changes and assessment findings, and protected from unauthorized disclosure and modification. 3 enhancements.

Maintained by Gerard Blokdyk

Other controls in PL: Planning – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.