PM-1Information Security Program Plan
Develop and disseminate an organization-wide information security program plan that:
Provides an overview of the requirements for the security program and a description of the security program management controls and common controls in place or planned for meeting those requirements;
Includes the identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance;
Reflects the coordination among organizational entities responsible for information security; and
Is approved by a senior official with responsibility and accountability for the risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation;
Review and update the organization-wide information security program plan {{ insert: param, pm-01_odp.01 }} and following {{ insert: param, pm-01_odp.02 }} ; and
Protect the information security program plan from unauthorized disclosure and modification.
PM-2Information Security Program Leadership Role
Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program.
PM-3Information Security and Privacy Resources
Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document all exceptions to this requirement;
Prepare documentation required for addressing information security and privacy programs in capital planning and investment requests in accordance with applicable laws, executive orders, directives, policies, regulations, standards; and
Make available for expenditure, the planned information security and privacy resources.
PM-4Plan of Action and Milestones Process
Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems:
Are developed and maintained;
Document the remedial information security, privacy, and supply chain risk management actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation; and
Are reported in accordance with established reporting requirements.
Review plans of action and milestones for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
PM-5System Inventory
Develop and update {{ insert: param, pm-05_odp }} an inventory of organizational systems.
PM-6Measures of Performance
Develop, monitor, and report on the results of information security and privacy measures of performance.
PM-7Enterprise Architecture
Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations and assets, individuals, other organizations, and the Nation.
PM-8Critical Infrastructure Plan
Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.
PM-9Risk Management Strategy
Develops a comprehensive strategy to manage:
Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and
Privacy risk to individuals resulting from the authorized processing of personally identifiable information;
Implement the risk management strategy consistently across the organization; and
Review and update the risk management strategy {{ insert: param, pm-09_odp }} or as required, to address organizational changes.
PM-10Authorization Process
Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes;
Designate individuals to fulfill specific roles and responsibilities within the organizational risk management process; and
Integrate the authorization processes into an organization-wide risk management program.
PM-11Mission and Business Process Definition
Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation; and
Determine information protection and personally identifiable information processing needs arising from the defined mission and business processes; and
Review and revise the mission and business processes {{ insert: param, pm-11_odp }}.
PM-12Insider Threat Program
Implement an insider threat program that includes a cross-discipline insider threat incident handling team.
PM-13Security and Privacy Workforce
Establish a security and privacy workforce development and improvement program.
PM-14Testing, Training, and Monitoring
Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems:
Are developed and maintained; and
Continue to be executed; and
Review testing, training, and monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
PM-15Security and Privacy Groups and Associations
Establish and institutionalize contact with selected groups and associations within the security and privacy communities:
To facilitate ongoing security and privacy education and training for organizational personnel;
To maintain currency with recommended security and privacy practices, techniques, and technologies; and
To share current security and privacy information, including threats, vulnerabilities, and incidents.
PM-16Threat Awareness Program
Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence.
PM-17Protecting Controlled Unclassified Information on External Systems
Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in accordance with applicable laws, executive orders, directives, policies, regulations, and standards; and
Review and update the policy and procedures {{ insert: param, pm-17_prm_1 }}.
PM-18Privacy Program Plan
Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency’s privacy program, and:
Includes a description of the structure of the privacy program and the resources dedicated to the privacy program;
Provides an overview of the requirements for the privacy program and a description of the privacy program management controls and common controls in place or planned for meeting those requirements;
Includes the role of the senior agency official for privacy and the identification and assignment of roles of other privacy officials and staff and their responsibilities;
Describes management commitment, compliance, and the strategic goals and objectives of the privacy program;
Reflects coordination among organizational entities responsible for the different aspects of privacy; and
Is approved by a senior official with responsibility and accountability for the privacy risk being incurred to organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation; and
Update the plan {{ insert: param, pm-18_odp }} and to address changes in federal privacy laws and policy and organizational changes and problems identified during plan implementation or privacy control assessments.
PM-19Privacy Program Leadership Role
Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy program.
PM-20Dissemination of Privacy Program Information
Maintain a central resource webpage on the organization’s principal public website that serves as a central source of information about the organization’s privacy program and that:
Ensures that the public has access to information about organizational privacy activities and can communicate with its senior agency official for privacy;
Ensures that organizational privacy practices and reports are publicly available; and
Employs publicly facing email addresses and/or phone lines to enable the public to provide feedback and/or direct questions to privacy offices regarding privacy practices.
PM-21Accounting of Disclosures
Develop and maintain an accurate accounting of disclosures of personally identifiable information, including:
Date, nature, and purpose of each disclosure; and
Name and address, or other contact information of the individual or organization to which the disclosure was made;
Retain the accounting of disclosures for the length of the time the personally identifiable information is maintained or five years after the disclosure is made, whichever is longer; and
Make the accounting of disclosures available to the individual to whom the personally identifiable information relates upon request.
PM-22Personally Identifiable Information Quality Management
Develop and document organization-wide policies and procedures for:
Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle;
Correcting or deleting inaccurate or outdated personally identifiable information;
Disseminating notice of corrected or deleted personally identifiable information to individuals or other appropriate entities; and
Appeals of adverse decisions on correction or deletion requests.
PM-23Data Governance Body
Establish a Data Governance Body consisting of {{ insert: param, pm-23_odp.01 }} with {{ insert: param, pm-23_odp.02 }}.
PM-24Data Integrity Board
Establish a Data Integrity Board to:
Review proposals to conduct or participate in a matching program; and
Conduct an annual review of all matching programs in which the agency has participated.
PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research
Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research;
Limit or minimize the amount of personally identifiable information used for internal testing, training, and research purposes;
Authorize the use of personally identifiable information when such information is required for internal testing, training, and research; and
Review and update policies and procedures {{ insert: param, pm-25_prm_1 }}.
PM-26Complaint Management
Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes:
Mechanisms that are easy to use and readily accessible by the public;
All information necessary for successfully filing complaints;
Tracking mechanisms to ensure all complaints received are reviewed and addressed within {{ insert: param, pm-26_prm_1 }};
Acknowledgement of receipt of complaints, concerns, or questions from individuals within {{ insert: param, pm-26_odp.03 }} ; and
Response to complaints, concerns, or questions from individuals within {{ insert: param, pm-26_odp.04 }}.
PM-27Privacy Reporting
Develop {{ insert: param, pm-27_odp.01 }} and disseminate to:
{{ insert: param, pm-27_odp.02 }} to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and
{{ insert: param, pm-27_odp.03 }} and other personnel with responsibility for monitoring privacy program compliance; and
Review and update privacy reports {{ insert: param, pm-27_odp.04 }}.
PM-28Risk Framing
Identify and document:
Assumptions affecting risk assessments, risk responses, and risk monitoring;
Constraints affecting risk assessments, risk responses, and risk monitoring;
Priorities and trade-offs considered by the organization for managing risk; and
Organizational risk tolerance;
Distribute the results of risk framing activities to {{ insert: param, pm-28_odp.01 }} ; and
Review and update risk framing considerations {{ insert: param, pm-28_odp.02 }}.
PM-29Risk Management Program Leadership Roles
Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and
Establish a Risk Executive (function) to view and analyze risk from an organization-wide perspective and ensure management of risk is consistent across the organization.
PM-30Supply Chain Risk Management Strategy
Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services;
Implement the supply chain risk management strategy consistently across the organization; and
Review and update the supply chain risk management strategy on {{ insert: param, pm-30_odp }} or as required, to address organizational changes.
PM-31Continuous Monitoring Strategy
Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include:
Establishing the following organization-wide metrics to be monitored: {{ insert: param, pm-31_odp.01 }};
Establishing {{ insert: param, pm-31_odp.02 }} and {{ insert: param, pm-31_odp.03 }} for control effectiveness;
Ongoing monitoring of organizationally-defined metrics in accordance with the continuous monitoring strategy;
Correlation and analysis of information generated by control assessments and monitoring;
Response actions to address results of the analysis of control assessment and monitoring information; and
Reporting the security and privacy status of organizational systems to {{ insert: param, pm-31_prm_4 }} {{ insert: param, pm-31_prm_5 }}.
PM-32Purposing
Analyze {{ insert: param, pm-32_odp }} supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended purpose.