NIST SP 800-53 Rev 5
PM - Program Management

NIST SP 800-53 Rev 5 NIST800-PM-4: PM-4 Plan of Action and Milestones Process

a. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems: 1. Are developed and maintained; 2. Document the remedial information security, privacy, and supply chain risk management actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation; and 3. Are reported in accordance with established reporting requirements. b. Review plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 31 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 4 controls

  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption

APRA CPS 234 · 2 controls

  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • 36 Para 36 Notify APRA of material control weaknesses within 10 business days

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 5.27 Learning from information security incidents
  • 5.36 Compliance with policies, rules and standards for information security

ISO 27701:2019 · 2 controls

  • 5.6.1 Operational planning and control
  • 5.8.1 Nonconformity and corrective action

ISO/IEC 42001:2023 · 2 controls

  • 10.2 Nonconformity and corrective action
  • 8.1 Operational planning and control
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • CPS220-P50 Qualification of the Risk Management Declaration
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses

C5 (Germany) · 1 control

  • C5-OPS-22 Testing and Documentation of known Vulnerabilities
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

CIS Controls v8 · 1 control

  • CIS-7.2 Establish and Maintain a Remediation Process

DORA · 1 control

  • DORA-Art.50 Administrative penalties and remedial measures

EU AI Act · 1 control

ISO 22301:2019 · 1 control

  • 10.2 Continual improvement

ISO 27002:2022 · 1 control

  • 5.36 Compliance with policies, rules and standards for information security

NIS2 Directive · 1 control

  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

PCI DSS 4.0 · 1 control

  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PM - Program Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PM-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 31 it maps to, and the evidence behind each claim, over MCP and REST.