Appendix C: Security Policies and Procedures
MVP Key Points Include:
Each -1 control should havelinksentries to the relevant plolicy and procedure documents
This is not normalized and is only for legacy conversion MVP
Normalized Key points include:
attach each document as back-matter/resourcesentriesFrom each component, add alinksentry that references theresource(#uuid-value)
create a component for each policy documentcreate a component for each procedure documenteach -1 control hasby-componentsentries that cite the appropriate policy and procedure components
Reference Components [need citation - there may be a page for document-type compnents ] andSee AttachmentsControl pages.Response: Don't duplicate those explanations here.
Policies and procedures are required by the first control in each NIST SP 800-53 control family, commonly refered to as the "dash one" or "-1 controls"Procedures.