CCI-000080
CCI-000080 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to ensure that all capital planning and investment requests include the resources needed to implement the information security program and documents all exceptions to this requirement.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process to ensure the organization being inspected/assessed ensures that all capital planning and investment requests include the resources needed to implement the information security program and documents all exceptions to this requirement.
Compelling Evidence
1.) Signed and dated planning documentation that describes how the site ensures capital planning and investment requests include the resources needed to implement the information security program. 2.) Documentation of all exceptions to capital planning and investment requests.