Policy and Procedures PL-1
Planning · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PL-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Planning family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PL-1 (Policy and Procedures) is about putting the Planning family on paper: a written planning policy that states its purpose, scope, and who it applies to, plus the procedures that make it real. It also names an official to own the policy and sets a rhythm for reviewing and updating it. It is a foundational Planning control at the Low baseline.
What good looks like
- Write a planning policy that states its purpose, scope, and who it applies to.
- Cover roles and responsibilities, management commitment, and how teams coordinate.
- Write procedures that turn the policy into repeatable, day-to-day steps.
- Name an official who owns the policy — keeps it current and makes sure people see it.
- Review and update the policy and procedures on a set schedule and after any major change.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
How to move it toward Implemented
- Draft a one-page planning policy for the lab server: purpose, scope, who it covers, and the named owner.
- Write the matching procedures — how the server is planned, categorized, and documented — and store both in
/etc/security/policies/or your evidence folder. - Set a review cadence (for example, yearly and after any major change) and record the last-reviewed date in the document.
- Attach that policy-and-procedure document as hardening evidence on the asset, naming
PL-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.