unified
UC-GOV-18 — Document and approve system security and privacy plans
Develop, approve, and maintain security and privacy plans for systems that describe each system's authorized purpose, boundary, operating context and concept of operations, requirements, and the controls in place or planned. Distribute plans to authorized personnel, protect them from unauthorized disclosure and modification, review them at defined intervals, and update them to address changes — verifying that systems continue to be used only for their intended and authorized purposes.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-18
- title
- Document and approve system security and privacy plans
- statement
- Develop, approve, and maintain security and privacy plans for systems that describe each system's authorized purpose, boundary, operating context and concept of operations, requirements, and the controls in place or planned. Distribute plans to authorized personnel, protect them from unauthorized disclosure and modification, review them at defined intervals, and update them to address changes — verifying that systems continue to be used only for their intended and authorized purposes.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PL-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PL-7
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-32
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-18 — Document and approve system security and privacy plans mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Maintained, approved system security plans keep each system's control set defined and current.
- System Categorization, Security Planning & Authorization operates UC-GOV-18 — Document and approve system security and privacy plans
- UC-GOV-18 — Document and approve system security and privacy plans maps_to PL-7 — Concept of Operations
- framework
- nist-800-53
- control_id
- PL-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-18 — Document and approve system security and privacy plans maps_to PM-32 — Purposing
- framework
- nist-800-53
- control_id
- PM-32
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-18 — Document and approve system security and privacy plans maps_to PL-2 — System Security and Privacy Plans
- framework
- nist-800-53
- control_id
- PL-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- NIST RMF System Authorization (ATO) Cycle oversees UC-GOV-18 — Document and approve system security and privacy plans