An information security plan sets out how information security risk is managed and kept consistent with enterprise strategy and architecture. Recommendations for improvement rest on business cases that have been approved; they are delivered as part of developing services and solutions and then run as an integral part of business operations. A risk treatment plan, consistent with strategic objectives and the architecture, names the most suitable management practices and security solutions, together with the resources, responsibilities and priorities needed to manage the risks identified. The architecture holds an inventory of the solution components that manage security-related risk. Proposals to carry out the plan are backed by business cases that address funding and roles. Input is provided to the design and development of the practices and solutions chosen. Training and awareness programmes on information security and privacy are put in place. Security and privacy procedures and controls are planned, designed, implemented and monitored in an integrated way so that security events are prevented, detected and responded to promptly. How effective the chosen practices are is measured so that results can be compared and repeated.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.