PL-8—Security and Privacy Architectures
>Control Description
Develop security and privacy architectures for the system that:
Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information;
Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals;
Describe how the architectures are integrated into and support the enterprise architecture; and
Describe any assumptions about, and dependencies on, external systems and services;
Review and update the architectures ⚙organization-defined frequency to reflect changes in the enterprise architecture; and
Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.
>Related Controls
Ask AI
Configure your API key to use AI features.