# PM-8 — Critical Infrastructure Plan

- **Control ID:** PM-8
- **Family:** [PM](/md/families/PM.md)
- **Baselines:** No content available.
- **Enhancement of:** No content available.

## Description

Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.

## Discussion

Protection strategies are based on the prioritization of critical assets and resources. The requirement and guidance for defining critical infrastructure and key resources and for preparing an associated critical infrastructure protection plan are found in applicable laws, executive orders, directives, policies, regulations, standards, and guidelines.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [GV.OC-04](/md/csf/GV.OC-04.md) — Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
- [RC.RP-04](/md/csf/RC.RP-04.md) — Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

## Related controls

- [CP-2](/md/controls/CP-2.md)
- [CP-4](/md/controls/CP-4.md)
- [PE-18](/md/controls/PE-18.md)
- [PL-2](/md/controls/PL-2.md)
- [PM-9](/md/controls/PM-9.md)
- [PM-11](/md/controls/PM-11.md)
- [PM-18](/md/controls/PM-18.md)
- [RA-3](/md/controls/RA-3.md)
- [SI-12](/md/controls/SI-12.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
