CCI-003050
CCI-003050 Definition
Develop security and privacy plans for the system that are consistent with the organization's enterprise architecture.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines a security plan for the information system which is consistent with the organization's enterprise architecture.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the security plan and the enterprise architecture to ensure the organization's security plan for the information system is consistent with the organization's enterprise architecture.
Compelling Evidence
1.) Enterprise architecture documentation. 2.) System security plan (SSP) that is up-to-date, consistent with, and reflects the organization's current enterprise architecture.