{"data":{"id":"PM-08","name":"Critical Infrastructure Plan","family":"PM","family_name":"Program Management","withdrawn":false,"description":"Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.","supplemental_guidance":"Protection strategies are based on the prioritization of critical assets and resources. The requirement and guidance for defining critical infrastructure and key resources and for preparing an associated critical infrastructure protection plan are found in applicable laws, executive orders, directives, policies, regulations, standards, and guidelines.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"PM-08","name":"Critical Infrastructure Plan","description":"Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.","discussion":"Protection strategies are based on the prioritization of critical assets and resources. The requirement and guidance for defining critical infrastructure and key resources and for preparing an associated critical infrastructure protection plan are found in applicable laws, executive orders, directives, policies, regulations, standards, and guidelines.","related_controls":["CP-02","CP-04","PE-18","PL-02","PM-09","PM-11","PM-18","RA-03","SI-12"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Privacy added. Related controls updated."}},"compliance_mappings":{"iso_27001_2022":["4.1","4.2"],"iso_27002_2022":["5.31"],"cobit_2019":["APO02"],"pci_dss_v4":[],"nist_csf_2":["GV.OC-01","GV.OC-02","GV.OC-04","GV.OC-05","RC.RP-04"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":["SS1/21-3.1"],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["5.31"],"rbi_csf":["ITGRCA.4"],"fisc":[],"lgpd_bcb":["BCB.Art.11","BCB.Art.16"],"hkma_tme1":["TME1.2.2","TME1.6.1"],"mlps_2":[],"dnb_good_practice":["DNB.4.1","DNB.11.1"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-2","TM-14"],"cbuae":["CR-13"],"nca_ecc":["1-1","3-1"],"qatar_nia":["BC"],"uae_ia":["T12"],"bog_cisd":["CISD-BCM"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.7"],"sa_js2":["JS2-7.5"],"cpmi_pfmi":["CG.RR","PFMI.P3","PFMI.P17"],"ecb_croe":["CROE.2.2.3","CROE.2.5.2","CROE.2.5.3"],"ffiec_is":["II.A"],"hipaa_sr":["§164.308(b)(1)","§164.314(a)(1)","§164.314(b)(1)"],"nydfs_500":["500.9"],"sebi_cscrf":["BCP-DR","CCMP","GV.OC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.3"],"tiber_eu":["TIBER.XB"],"pci_hsm":[],"common_criteria":["CCRA"],"isae_3402":[],"fca_sysc_13":["SYSC 13.5.2"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["06.a","12.a"],"iso_27799":["17.1"],"lloyds_ms":["MS9.1"],"naic_ds":["4A"],"nhs_dspt":["NDG-7.1"],"pra_ss1_23":[],"solvency_ii":["Art.44(2)","DR.266"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings extracted from framework-coverage data 2026-10-03: nist_csf_2 RC.RP-04 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: privacy baseline added, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-034"]}}