UCF STIG Viewer Logo

PM-3 INFORMATION SECURITY RESOURCES


Overview

Number Title Impact Priority Subject Area
PM-3 Information Security Resources Program Management

Instructions
The organization:
PM-3a.
Ensures that all capital planning and investment requests include the resources needed to implement the information security program and documents all exceptions to this requirement;
PM-3b.
Employs a business case/Exhibit 300/Exhibit 53 to record the resources required; and
PM-3c.
Ensures that information security resources are available for expenditure as planned.
Guidance
Organizations consider establishing champions for information security efforts and as part of including the necessary resources, assign specialized expertise and resources as needed. Organizations may designate and empower an Investment Review Board (or similar group) to manage and provide oversight for the information security-related aspects of the capital planning and investment control process.

Enhancements