PL-08 Security and Privacy Architectures

Planning

Moderate High

Description

a. Develop security and privacy architectures for the system that: 1. Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information; 2. Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals; 3. Describe how the architectures are integrated into and support the enterprise architecture; and 4. Describe any assumptions about, and dependencies on, external systems and the services that those systems provide; and b. Review and update the architectures [Assignment: organization-defined frequency] to reflect changes in the enterprise architecture.

Supplemental Guidance

The security and privacy architectures at the system level are consistent with the organization-wide security and privacy architectures described in PM-07, which are integral to and developed as part of the enterprise architecture. The architectures include an architectural description, the allocation of security and privacy functionality (including controls), security- and privacy-related information for external interfaces, information being exchanged across the interfaces, and the protection mechanisms associated with each interface.

Changes from Rev 4

No significant changes from Rev 4.

Compliance Mappings

ISO 27002:2022

8.27

COBIT 2019

APO03BAI02

CIS Controls v8

CIS 12.2CIS 12.4CIS 3.8

NIST CSF 2.0

ID.AM-03

PRA Operational Resilience

SS1/21-5.2SS1/21-9.1

BSI IT-Grundschutz

NET.1.1

BIO2

8.27

RBI CSF

ITGRCA.4ITGRCA.24

HKMA TM-E-1

TME1.2.2TME1.7.1TME1.7.3

MLPS 2.0

8.1.9.2

DNB Good Practice

DNB.2.1DNB.3.2

EU CRA

CRA.I.1

SAMA CSF

1.1

CBB TM

TM-2TM-3

CBE CSF

GOV-1

SA JS2

JS2-4JS2-5

BoG CISD

CISD-ISMSCISD-XIII

BoM CTRM

1.33.13.7

BCBS 239

Principle 2Principle 6

CPMI-IOSCO PFMI

PFMI.P22

FFIEC IS

II.C.1II.C.2II.C.3

NYDFS 500

500.2

SEBI CSCRF

GV.OC

BOT Cyber Resilience

Ch6.2

10 CFR 73.54

73.54(c)(2)RG5.71-C-PL

TSA Pipeline SD

SD-2 Sec F

DOE C2M2 v2.1

ARCHITECTURE

API 1164

Sec 5

IAEA NSS 17-T

Sec 5.1

Common Criteria

CC Part 1 — PPCC Part 1 — ST

ISAE 3402

Clause 9

NAIC Insurance Data Security

44B

PRA SS1/23

P1.3P3.1

HITRUST CSF v11

10.a

FDA Cybersecurity Guidance

SPDF-1SPDF-3

Basel SCO60

SCO60.2