NIST SP 800-53 Revision 5.1 HIGH
PL Planning

NIST SP 800-53 Revision 5.1 HIGH PL-1: Policy and Procedures

Develop and review planning policy at least annually.

What else in your programme already covers this

This control maps to 38 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

HIPAA Security Rule · 5 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

SOC 2 · 4 controls

  • SOC2-CC3.4 COSO principle 9: Identifies and assesses changes that could impact internal controls
  • SOC2-CC4.1 COSO principle 16: Selects and develops ongoing and separate evaluations
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC5.3 COSO principle 12: Deploys control activities through policies and procedures

C5 (Germany) · 3 controls

  • C5-OIS-02 Information Security Policy
  • C5-SP-01 Documentation, communication and provision of policies and instructions
  • C5-SP-02 Review and Approval of Policies and Instructions

NIST SP 800-66 Rev 2 · 3 controls

PCI DSS 4.0 · 3 controls

  • 12.1.1 An overall information security policy is: • Established. • Published. • Maintained. • Disseminated to all relevant personnel, as well as to relevant vendors and business partners
  • 12.1.2 The information security policy is: • Reviewed at least once every 12 months. • Updated as needed to reflect changes to business objectives or risks to the environment
  • 12.1.4 CISO or equivalent responsibility
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-PS-1 Privacy Safeguard 1 - Open and transparent management of CDR data

ISO 27701:2019 · 2 controls

  • 6.15.1 Compliance with legal and contractual requirements
  • 6.2.1 Management direction for information security

APRA CPS 234 · 1 control

  • CPS234-19 Information Security Policy Framework
  • GS-1 Align organization roles, responsibilities and accountabilities

ISO 27001:2022 · 1 control

  • 5.1 Policies for information security

ISO 27002:2022 · 1 control

  • 5.1 Policies for information security

NIS2 Directive · 1 control

  • Art.21.2.a Policies on risk analysis and on information system security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PL Planning

Query this from an agent

The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.