Information Security Program Plan
LOW MODERATE HIGHRequirements NIST SOURCE
- 1.Provides an overview of the requirements for the security program and a description of the security program management controls and common controls in place or planned for meeting those requirements;
- 2.Includes the identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance;
- 3.Reflects the coordination among organizational entities responsible for information security; and
- 4.Is approved by a senior official with responsibility and accountability for the risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation;
Requirement Context
This element is part of PM-1 — Information Security Program Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-1 — Information Security Program Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PM-1 — Information Security Program Plan. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
An information security program plan is a formal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management controls and common controls in place or planned for meeting those requirements. An information security program plan can be represented in a single document or compilations of documents. Privacy program plans and supply chain risk management plans are addressed separately in PM-18 and SR-2 , respectively. An information security program plan documents implementation details about program management and common controls. The plan provides sufficient information about the controls (including specification of parameters for assignment and selection operations, explicitly or by reference) to enable implementations that are unambiguously compliant with the intent of the plan and a determination of the risk to be incurred if the plan is implemented as intended. Updates to information security program plans include organizational changes and problems identified during plan implementation or control assessments. Program management controls may be implemented at the organization level or the mission or business process level, and are essential for managing the organization’s information security program. Program management controls are distinct from common, system-specific, and hybrid controls because program management controls are independent of any particular system. Together, the individual system security plans and the organization-wide information security program plan provide complete coverage for the security controls employed within the organization. Common controls available for inheritance by organizational systems are documented in an appendix to the organization’s information security program plan unless the controls are included in a separate security plan for a system. The organization-wide information security program plan indicates which separate security plans contain descriptions of common controls. Events that may precipitate an update to the information security program plan include, but are not limited to, organization-wide assessment or audit findings, security incidents or breaches, or changes in laws, executive orders, directives, regulations, policies, standards, and guidelines.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PM-1 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency at which to review and update the organization-wide information security program plan is defined;
- events that trigger the review and update of the organization-wide information security program plan are defined;
- an organization-wide information security program plan is developed;
- the information security program plan is disseminated;
- the information security program plan provides an overview of the requirements for the security program;
- the information security program plan provides a description of the security program management controls in place or planned for meeting those requirements;
- the information security program plan provides a description of the common controls in place or planned for meeting those requirements;
- the information security program plan includes the identification and assignment of roles;
- the information security program plan includes the identification and assignment of responsibilities;
- the information security program plan addresses management commitment;
- the information security program plan addresses coordination among organizational entities;
- the information security program plan addresses compliance;
- the information security program plan reflects the coordination among the organizational entities responsible for information security;
- the information security program plan is approved by a senior official with responsibility and accountability for the risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation;
- the information security program plan is reviewed and updated <PM-01_ODP[01] frequency>;
- the information security program plan is reviewed and updated following <PM-01_ODP[02] events>;
- the information security program plan is protected from unauthorized disclosure;
- the information security program plan is protected from unauthorized modification.
Examine
[SELECT FROM: Information security program plan; procedures addressing program plan development and implementation; procedures addressing program plan reviews and updates; procedures addressing coordination of the program plan with relevant entities; procedures for program plan approvals; records of program plan reviews and updates; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with information security program planning and plan implementation responsibilities; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for information security program plan development, review, update, and approval; mechanisms supporting and/or implementing the information security program plan].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PM-1. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Information security program plan
- procedures addressing program plan development and implementation
- procedures addressing program plan reviews and updates
- procedures addressing coordination of the program plan with relevant entities
- procedures for program plan approvals
- records of program plan reviews and updates
Testing
- Organizational processes for information security program plan development, review, update, and approval
- mechanisms supporting and/or implementing the information security program plan
Other Records
- other relevant documents or records