CCI-004344
CCI-004344 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - information security issues are addressed in the development of a critical infrastructure and key resources protection plan. - information security issues are addressed in the documentation of a critical infrastructure and key resources protection plan. - information security issues are addressed in the update of a critical infrastructure and key resources protection plan. - privacy issues are addressed in the development of a critical infrastructure and key resources protection plan. - privacy issues are addressed in the documentation of a critical infrastructure and key resources protection plan. - privacy issues are addressed in the update of a critical infrastructure and key resources protection plan.
Validation Procedures
Examine: [SELECT FROM: Information security program plan; privacy program plan; critical infrastructure and key resources protection plan; procedures addressing the development, documentation, and updating of the critical infrastructure and key resources protection plan; HSPD 7; National Infrastructure Protection Plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with information security and privacy program planning and plan implementation responsibilities; organizational personnel responsible for developing, documenting, and updating the critical infrastructure and key resources protection plan; organizational personnel with information security and privacy responsibilities]. Test: [SELECT FROM: Organizational processes for developing, documenting, and updating the critical infrastructure and key resources protection plan; mechanisms supporting the development, documentation, and updating of the critical infrastructure and key resources protection plan].