PM-15 Security and Privacy Groups and Associations

Program Management

Description

Establish and institutionalize contact with selected groups and associations within the security and privacy communities: a. To facilitate ongoing security and privacy education and training for organizational personnel; b. To maintain currency with recommended security and privacy practices, techniques, and technologies; and c. To share current security and privacy-related information including threats, vulnerabilities, and incidents.

Supplemental Guidance

Ongoing contact with security and privacy groups and associations is important in an environment of rapidly changing technologies and threats. Groups and associations include special interest groups, professional associations, forums, news groups, users' groups, and peer groups of security and privacy professionals in similar organizations. Organizations select security and privacy groups and associations based on the mission and business functions of the organization.

Changes from Rev 4

Title changed. Privacy added throughout.

Compliance Mappings

ISO 27001:2022

A.5.5A.5.6

ISO 27002:2022

5.55.6

COBIT 2019

APO08

CIS Controls v8

CIS 17.2

NIST CSF 2.0

GV.OC-02GV.RM-05ID.RA-02ID.RA-08RS.CO-03

CSA CCM v4

GRC-08SEF-08

CSA AICM v1

GRC-08GRC-15SEF-08

NIS2 Directive

Art. 29

EU DORA

Art.45(1)

BIO2

5.55.6

RBI CSF

Annex1.11ITGRCA.10

MLPS 2.0

8.1.7.2

DNB Good Practice

DNB.16.4DNB.3.1

EU CRA

CRA.Art14CRA.II.4CRA.II.5CRA.II.6CRA.Info.2

SAMA CSF

1.6

UAE IA

T1

CBB TM

TM-3

Qatar NIA

GV

CBUAE

CR-11

CBE CSF

GOV-3GOV-4

SA JS2

JS2-7.6

CBN CSF

Part4Part8

BoM CTRM

3.84.15.3

IOSCO Cyber Resilience

GOV-5LE-3REG-1RR-4SA-1SA-2

BCBS 239

Principle 14

CPMI-IOSCO PFMI

CG.SA

FFIEC IS

II.AII.A.1III.A

NYDFS 500

500.10

ECB CROE

CROE.2.2.3CROE.2.5.3CROE.2.7.1CROE.2.7.2CROE.2.8.2

SEBI CSCRF

CAPACITYPR.ATRS.CO

BOT Cyber Resilience

Ch1.3Ch8.1

10 CFR 73.54

73.54(d)

TSA Pipeline SD

SD-1 Sec 2

DOE C2M2 v2.1

THREAT

CBEST

CBEST.2

TIBER-EU

TIBER.GTLTIBER.XB

Lloyd's Minimum Standards

CRM.2

FDA Cybersecurity Guidance

524B-2524B-3CVD-1CVD-2MON-1MON-3

ISO 27799

16.116.3

Basel SCO60

SCO60.84