NIST SP 800-53 Rev 5
PL - Planning

NIST SP 800-53 Rev 5 NIST800-PL-2: PL-2 System Security and Privacy Plans

a. Develop security and privacy plans for the system that: 1. Are consistent with the organization’s enterprise architecture; 2. Explicitly define the constituent system components; 3. Describe the operational context of the system in terms of mission and business processes; 4. Identify the individuals that fulfill system roles and responsibilities; 5. Identify the information types processed, stored, and transmitted by the system; 6. Provide the security categorization of the system, including supporting rationale; 7. Describe any specific threats to the system that are of concern to the organization; 8. Provide the results of a privacy risk assessment for systems processing personally identifiable information; 9. Describe the operational environment for the system and any dependencies on or connections to other systems or system components; 10. Provide an overview of the security and privacy requirements for the system; 11. Identify any relevant control baselines or overlays, if applicable; 12. Describe the controls in place or planned for meeting the security and privacy requirements, including a rationale for any tailoring decisions; 13. Include risk determinations for security and privacy architecture and design decisions; 14. Include security- and privacy-related activities affecting the system that require planning and coordination with [Assignment: organization-defined individuals or groups]; and 15. Are reviewed and approved by the authorizing official or designated representative prior to plan implementation. b. Distribute copies of the plans and communicate subsequent changes to the plans to [Assignment: organization-defined personnel or roles]; c. Review the plans [Assignment: organization-defined frequency]; d. Update the plans to address changes to the system and environment of operation or problems identified during plan implementation or control assessments; and e. Protect the plans from unauthorized disclosure and modification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 62 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 8 controls

  • 5.2.4 Information security management system
  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 5.5.5 Documented information
  • 5.6.1 Operational planning and control
  • 6.11.1 Security requirements of information systems
  • 6.2.1 Management direction for information security
  • 7.2.5 Privacy impact assessment

PCI DSS 4.0 · 8 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 3.1.1 3.1.1 Requirement 3 policies and procedures maintained and in use
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change

ISO 22301:2019 · 4 controls

  • 4.3.2 Scope of the business continuity management system
  • 7.5 Documented information
  • 7.5.2 Creating and updating
  • 8.4.4 Business continuity plans

SOC 2 · 4 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-P1.1 P1.1 Privacy notice to data subjects

ISO/IEC 42001:2023 · 3 controls

  • 4.3 Determining the scope of the AI management system
  • 7.5 Documented information
  • A.6.2.3 Documentation of AI system design and development

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 5.37 Documented operating procedures
  • 5.8 Information security in project management

ISO 27002:2022 · 2 controls

  • 5.37 Documented operating procedures
  • 5.8 Information security in project management
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

NIST SP 800-160 · 2 controls

  • CPS230-P27 Comprehensive Assessment of the Operational Risk Profile
  • SEC01-BP03 Identify and validate control objectives
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

C5 (Germany) · 1 control

  • CFTC-SS-1 Program of Risk Analysis and Oversight

CIS Controls v8 · 1 control

CMMC 2.0 · 1 control

  • ITSG33-RMP-4 Security Control Selection and Profiles (Annex 4A)

EU AI Act · 1 control

FedRAMP High · 1 control

  • PL-2 System Security and Privacy Plans

FedRAMP Moderate · 1 control

  • PL-2 System Security and Privacy Plans

GDPR · 1 control

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-172 · 1 control

  • 3.11.4e Security Solution Rationale Document

NIST SP 800-187 · 1 control

NIST SP 800-207 · 1 control

  • PL-2 PL-2 System Security and Privacy Plans
  • PL-2 PL-2 System Security and Privacy Plans
  • PL-2 PL-2 System Security and Privacy Plans

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PL - Planning

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PL-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 62 it maps to, and the evidence behind each claim, over MCP and REST.