|
controlPL-8
Security and Privacy Architectures (PL-8)
Develop security and privacy architectures for the system that: Review and update the architectures [organization-defined] to reflect changes in the enterprise architecture; and Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.
Security Baselines
MODERATEHIGHLOW
planningsecurity-plan
Why These Connect
Maps To3
These are equivalent or closely aligned requirements in other frameworks.
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports24
These related controls work together — a change to one may affect the others.
Enhances2
These enhancements add specific capabilities or refinements to the base control.
Related Controls(17)
CM-2Baseline Configuration (CM-2)
LMH
CM-6Configuration Settings (CM-6)LMH
PL-2System Security and Privacy Plans (PL-2)LMH
PL-7Concept of Operations (PL-7)PL-9Central Management (PL-9)PM-5System Inventory (PM-5)PM-7Enterprise Architecture (PM-7)RA-9Criticality Analysis (RA-9)MH
SA-3System Development Life Cycle (SA-3)LMH
SA-5System Documentation (SA-5)LMH
SA-8Security and Privacy Engineering Principles (SA-8)LMH
SA-17Developer Security and Privacy Architecture and Design (SA-17)H
SC-7Boundary Protection (SC-7)LMH
SA-24Design For Cyber Resiliency (SA-24)SC-29Heterogeneity (SC-29)SC-36Distributed Processing and Storage (SC-36)SR-3Supply Chain Controls and Processes (SR-3)LMH
Cross-Framework Mappings(3)
ID.AM-03ID.AM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.AM-03ID.AM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5