NIST SP 800-171 Rev 3
03.15 PL (Planning)

NIST SP 800-171 Rev 3 03.15.02: System Security Plan

Develop, document, and maintain a system security plan describing the system boundary, environment of operation, security requirements implementation, and connections to other systems.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 41 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 4 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)

C5 (Germany) · 3 controls

  • C5-COS-07 Documentation of the network topology
  • C5-OIS-01 Information Security Management System (ISMS)
  • C5-OIS-02 Information Security Policy

HIPAA Security Rule · 3 controls

NIS2 Directive · 3 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence

PCI DSS 4.0 · 3 controls

  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

ISO 27701:2019 · 2 controls

  • 5.2.3 Determining the scope of the information security management system
  • 5.5.5 Documented information
  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

NIST SP 800-66 Rev 2 · 2 controls

  • ANSSI-HYG-04 Identify the Most Sensitive Information and Servers and Maintain a Network Diagram
  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile

APRA CPS 234 · 1 control

  • CPS234-19 Information Security Policy Framework
  • SEC01-BP03 Identify and validate control objectives
  • GS-1 Align organization roles, responsibilities and accountabilities
  • CFTC-SS-1 Program of Risk Analysis and Oversight

CIS Controls v8 · 1 control

  • CIS-12.4 Establish and Maintain Architecture Diagram(s)

CMMC 2.0 · 1 control

FedRAMP High · 1 control

  • PL-2 System Security and Privacy Plans

FedRAMP Moderate · 1 control

  • PL-2 System Security and Privacy Plans

ISO 27001:2022 · 1 control

  • 5.37 Documented operating procedures

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.15 PL (Planning)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.15.02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 41 it maps to, and the evidence behind each claim, over MCP and REST.