PM-03 Information Security and Privacy Resources

Program Management

Description

a. Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document all exceptions to this requirement; b. Prepare documentation required for addressing information security and privacy programs in capital planning and investment requests in accordance with applicable laws, executive orders, directives, policies, regulations, standards; and c. Make available for expenditure, the planned information security and privacy resources.

Supplemental Guidance

Organizations consider establishing champions for information security and privacy and, as part of including the necessary resources, assign specialized expertise and resources as needed. Organizations may designate and empower an Investment Review Board or similar group to manage and provide oversight for the information security and privacy aspects of the capital planning and investment control process.

Changes from Rev 4

Title changed from 'Information Security Resources' to 'Information Security and Privacy Resources'. Privacy added throughout.

Compliance Mappings

ISO 27001:2022

4.46.27.1

COBIT 2019

APO01APO06APO13EDM01EDM02EDM04

NIST CSF 2.0

GV.RR-03

CSA CCM v4

GRC-05

CSA AICM v1

GRC-05

IEC 62443

2-1 4.2

MAS TRM

3

APRA CPS 234

Para 15Para 19-20

BSI IT-Grundschutz

ISMS.1

RBI CSF

ITGRCA.4ITGRCA.5

FISC Security Guidelines

FISC.O1

HKMA TM-E-1

TME1.2.1

DNB Good Practice

DNB.4.3DNB.5.2

SAMA CSF

1.1

NCA ECC

1-2

UAE IA

T1

CBB TM

TM-1

Qatar NIA

GV

CBUAE

CR-1

CBE CSF

GOV-1

SA JS2

JS2-4

CBN CSF

Part1.1

BoG CISD

CISD-ICISD-IICISD-ISMS

POPIA

s8

BoM CTRM

1.1

BCBS 239

Principle 1

CPMI-IOSCO PFMI

CG.GOVPFMI.P15PFMI.P2

FFIEC IS

I.BI.C

NYDFS 500

500.2500.4

HIPAA Security Rule

§164.308(a)(1)(i)§164.316(a)

ECB CROE

CROE.2.1.1

EBA ICT Guidelines

3.2.23.6.1

BOT Cyber Resilience

Ch1.1

NERC CIP

CIP-003-9

10 CFR 73.54

73.54(b)

DOE C2M2 v2.1

PROGRAM

AWIA

AWWA Sec 1

IAEA NSS 17-T

Sec 3

Solvency II

EIOPA-ICT-4.1

NAIC Insurance Data Security

44C

PRA SS1/23

P2.1

HITRUST CSF v11

00.a04.a