← Controls / PL

PL-08 Security and Privacy Architectures

Planning

Moderate High Privacy

Description

a. Develop security and privacy architectures for the system that: 1. Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information; 2. Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals; 3. Describe how the architectures are integrated into and support the enterprise architecture; and 4. Describe any assumptions about, and dependencies on, external systems and services; b. Review and update the architectures [Assignment: organization-defined frequency] to reflect changes in the enterprise architecture; and c. Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.

Supplemental Guidance

The security and privacy architectures at the system level are consistent with the organization-wide security and privacy architectures described in PM-07, which are integral to and developed as part of the enterprise architecture. The architectures include an architectural description, the allocation of security and privacy functionality (including controls), security- and privacy-related information for external interfaces, information being exchanged across the interfaces, and the protection mechanisms associated with each interface. The architectures can also include other information, such as user roles and the access privileges assigned to each role; security and privacy requirements; types of information processed, stored, and transmitted by the system; supply chain risk management requirements; restoration priorities of information and system services; and other protection needs. [SP 800-160-1] provides guidance on the use of security architectures as part of the system development life cycle process. [OMB M-19-03] requires the use of the systems security engineering concepts described in [SP 800-160-1] for high value assets. Security and privacy architectures are reviewed and updated throughout the system development life cycle, from analysis of alternatives through review of the proposed architecture in the RFP responses to the design reviews before and during implementation (e.g., during preliminary design reviews and critical design reviews). In today’s modern computing architectures, it is becoming less common for organizations to control all information resources. There may be key dependencies on external information services and service providers. Describing such dependencies in the security and privacy architectures is necessary for developing a comprehensive mission and business protection strategy. Establishing, developing, documenting, and maintaining under configuration control a baseline configuration for organizational systems is critical to implementing and maintaining effective architectures. The development of the architectures is coordinated with the senior agency information security officer and the senior agency official for privacy to ensure that the controls needed to support security and privacy requirements are identified and effectively implemented. In many circumstances, there may be no distinction between the security and privacy architecture for a system. In other circumstances, security objectives may be adequately satisfied, but privacy objectives may only be partially satisfied by the security requirements. In these cases, consideration of the privacy requirements needed to achieve satisfaction will result in a distinct privacy architecture. The documentation, however, may simply reflect the combined architectures. PL-08 is primarily directed at organizations to ensure that architectures are developed for the system and, moreover, that the architectures are integrated with or tightly coupled to the enterprise architecture. In contrast, SA-17 is primarily directed at the external information technology product and system developers and integrators. SA-17, which is complementary to PL-08, is selected when organizations outsource the development of systems or components to external entities and when there is a need to demonstrate consistency with the organization’s enterprise architecture and security and privacy architectures.

Changes from Rev 4

No significant changes from Rev 4.

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

PL-08(01) Defense in Depth

Design the security and privacy architectures for the system using a defense-in-depth approach that: a. Allocates [Assignment: organization-defined controls] to [Assignment: organization-defined locations and architectural layers]; and b. Ensures that the allocated controls operate in a coordinated and mutually reinforcing manner.

PL-08(02) Supplier Diversity

Require that [Assignment: organization-defined controls] allocated to [Assignment: organization-defined locations and architectural layers] are obtained from different suppliers.

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.8

ISO 27002:2022

8.27

COBIT 2019

APO03BAI02

CIS Controls v8

CIS 3.8CIS 12.2CIS 12.4

NIST CSF 2.0

ID.AM-03

PRA Operational Resilience

SS1/21-5.2SS1/21-9.1

BSI IT-Grundschutz

NET.1.1

BIO2

8.27

RBI CSF

ITGRCA.4ITGRCA.24

HKMA TM-E-1

TME1.2.2TME1.7.1TME1.7.3

MLPS 2.0

8.1.9.2

DNB Good Practice

DNB.2.1DNB.3.2

EU CRA

CRA.I.1

SAMA CSF

1.1

CBB TM

TM-2TM-3

CBE CSF

GOV-1

SA JS2

JS2-4JS2-5

BoG CISD

CISD-ISMSCISD-XIII

BoM CTRM

1.33.13.7

BCBS 239

Principle 2Principle 6

CPMI-IOSCO PFMI

PFMI.P22

FFIEC IS

II.C.1II.C.2II.C.3

NYDFS 500

500.2

SEBI CSCRF

GV.OC

BOT Cyber Resilience

Ch6.2

10 CFR 73.54

73.54(c)(2)RG5.71-C-PL

TSA Pipeline SD

SD-2 Sec F

DOE C2M2 v2.1

ARCHITECTURE

API 1164

Sec 5

IAEA NSS 17-T

Sec 5.1

Common Criteria

CC Part 1 — PPCC Part 1 — ST

ISAE 3402

Clause 9

NAIC Insurance Data Security

44B

PRA SS1/23

P1.3P3.1

HITRUST CSF v11

10.a

FDA Cybersecurity Guidance

SPDF-1SPDF-3

Basel SCO60

SCO60.2