|
controlPM-10

Authorization Process (PM-10)

Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes; Designate individuals to fulfill specific roles and responsibilities within the organizational risk management process; and Integrate the authorization processes into an organization-wide risk management program.

program-managementgovernancestrategy

Why These Connect

Maps To1

These are equivalent or closely aligned requirements in other frameworks.

Supports10

These related controls work together — a change to one may affect the others.

Cross-Framework Mappings(1)

ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022