| name | PM-3_information-security-and-privacy-resources |
| description | Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document al... |
| category | configuration |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","pm-3","pm"] |
| tech_stack | ["any"] |
| cwe_ids | [] |
| chains_with | ["PM-4","SA-2"] |
| prerequisites | [] |
| severity_boost | {"PM-4":"Chain with PM-4 for comprehensive security coverage","SA-2":"Chain with SA-2 for comprehensive security coverage"} |
PM-3 Information Security and Privacy Resources
High-Level Description
Family: Program Management (PM)
Framework: NIST SP 800-53 Rev 5
Organizations consider establishing champions for information security and privacy and, as part of including the necessary resources, assign specialized expertise and resources as needed. Organizations may designate and empower an Investment Review Board or similar group to manage and provide oversight for the information security and privacy aspects of the capital planning and investment control process.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for PM-3 implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| Manual Review | Documentation and interview-based | N/A |
Remediation Guide
Control Statement
Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document all exceptions to this requirement;
Prepare documentation required for addressing information security and privacy programs in capital planning and investment requests in accordance with applicable laws, executive orders, directives, policies, regulations, standards; and
Make available for expenditure, the planned information security and privacy resources.
Implementation Guidance
Organizations consider establishing champions for information security and privacy and, as part of including the necessary resources, assign specialized expertise and resources as needed. Organizations may designate and empower an Investment Review Board or similar group to manage and provide oversight for the information security and privacy aspects of the capital planning and investment control process.