PM-8: Critical Infrastructure Plan

PM-08 requires your organization to develop, document, and maintain a plan that identifies critical infrastructure and key resources and

Quick-reference card

FieldValue
Control IDPM-08
Control NameCritical Infrastructure Plan
FrameworkNIST SP 800-53 Revision 5
Control FamilyProgram Management
BaselinesPRIVACY
RelevanceOrganization (First Party)
Risk SeverityLow

What this control requires

PM-08 requires your organization to develop, document, and maintain a plan that identifies critical infrastructure and key resources and defines how you’ll protect them. The control connects your security and privacy programs to national-level infrastructure protection requirements found in laws, executive orders, directives, and standards such as Homeland Security Presidential Directive 7 (HSPD 7) and the National Infrastructure Protection Plan.

In practice, this control means you can’t treat infrastructure protection as an afterthought layered onto existing security plans. Your critical infrastructure and key resources protection plan must address both information security and privacy considerations, and it must align with the prioritization strategies your organization uses to rank its most valuable assets. The plan isn’t a static document filed away after initial creation. It requires regular updates as your infrastructure landscape, regulatory obligations, and threat environment evolve.

The reason this requirement exists is that organizations operating critical infrastructure need a structured approach to identifying which assets matter most and how protection resources should be allocated across them. Without this plan, protection efforts become reactive and fragmented, leaving gaps that affect both the organization and the broader sectors it supports.

Why it matters

Most organizations that fall under NIST SP 800-53 privacy baselines treat PM-08 as a low-priority documentation exercise. That assumption creates risk during audits and regulatory reviews, where assessors expect to see a living, actively maintained critical infrastructure and key resources protection plan rather than a placeholder document.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Because PM-08 sits within the Program Management family, deficiencies here signal systemic weaknesses in your overall security and privacy governance, not just a single missing artifact. Assessors view program-level gaps as indicators that other operational controls may also lack adequate oversight.

What auditors flag

  • No documented critical infrastructure and key resources protection plan, or a plan that hasn’t been updated since initial creation
  • The plan doesn’t address both information security and privacy issues as separate, documented considerations
  • No evidence that the plan aligns with applicable laws, executive orders, or directives such as HSPD 7
  • Asset prioritization decisions aren’t traceable back to a defined methodology or risk-based criteria
  • The plan exists in isolation with no linkage to the organization’s broader risk management strategy or contingency planning

How to implement

For your organization

The most common failure with PM-08 isn’t the absence of a plan. It’s producing a document that checks a compliance box without reflecting how your organization actually prioritizes and protects its infrastructure.

Step 1: Identify critical infrastructure and key resources. Start by cataloging the assets, systems, and services your organization depends on for mission-critical operations. Map these assets against the sectors and categories defined in the National Infrastructure Protection Plan. Involve stakeholders from information security, privacy, operations, and business continuity teams to ensure the inventory reflects operational reality rather than just IT system boundaries.

Step 2: Establish prioritization criteria. Define how you’ll rank the criticality of each identified asset. Your prioritization should account for the impact of loss or degradation on organizational mission, the sensitivity of data processed or stored, dependencies between systems, and obligations under applicable regulations. Document the methodology so assessors can trace your protection decisions back to a repeatable process.

Step 3: Develop the protection plan. Draft a critical infrastructure and key resources protection plan that addresses both information security and privacy considerations. The plan should reference the specific laws, executive orders, directives, and standards that apply to your organization. Include protection strategies aligned with your asset prioritization, roles and responsibilities for plan execution, and coordination requirements with external stakeholders or sector-specific agencies.

Step 4: Align with existing program documentation. Your critical infrastructure protection plan shouldn’t exist in a vacuum. Link it to your information security program plan, privacy program plan, risk management strategy, and contingency plans. Cross-referencing these documents ensures consistency and prevents conflicting guidance.

Step 5: Establish a review and update cycle. Define a cadence for reviewing and updating the plan. Trigger updates when significant changes occur in your infrastructure, regulatory environment, or threat landscape. Document each revision with a change log that captures what changed and why.

Common mistakes to avoid:

  • Treating the plan as a one-time deliverable rather than a living document
  • Addressing information security without equally covering privacy considerations
  • Failing to reference the specific legal and regulatory drivers that apply to your sector
  • Creating the plan without input from privacy, operations, and business continuity stakeholders
  • Not maintaining evidence of plan reviews and updates for audit purposes
  • Overlooking sector-specific requirements such as NERC CIP for energy infrastructure
  • Ignoring incident reporting obligations that apply to critical infrastructure entities

Evidence examples

Evidence TypeExample Artifact
Program plansInformation security program plan and privacy program plan documenting organizational protection strategies and governance structures
Critical infrastructure protection planCritical infrastructure and key resources protection plan identifying prioritized assets, protection strategies, and responsible parties
Development and update proceduresDocumented procedures for developing, reviewing, and updating the critical infrastructure protection plan, including revision history and change logs
Regulatory and directive referencesRecords of applicable laws, executive orders (including HSPD 7), directives, and standards incorporated into the protection plan
Asset prioritization documentationMethodology and criteria used to prioritize critical assets and key resources, with traceability to risk-based decisions
Privacy impact documentationRecords demonstrating that privacy issues are addressed in the development and maintenance of the protection plan

Cross-framework mapping

No cross-framework mappings are currently configured for this control.

  • CP-02 — Contingency Plan: defines the contingency planning activities that protect critical infrastructure during disruptions, directly supporting the protection strategies outlined in PM-08
  • CP-04 — Contingency Plan Testing: validates that contingency measures for critical infrastructure work as intended through exercises and testing
  • PE-18 — Location of System Components: addresses the physical placement of system components, which factors into how critical infrastructure assets are protected
  • PL-02 — System Security and Privacy Plans: provides system-level security and privacy documentation that feeds into the organization-wide critical infrastructure protection plan
  • PM-09 — Risk Management Strategy: establishes the risk management approach that informs how critical infrastructure protection priorities are set
  • PM-11 — Mission and Business Process Definition: identifies mission and business processes that determine which infrastructure assets qualify as critical
  • PM-18 — Privacy Program Plan: documents the privacy program that must be reflected in the critical infrastructure protection plan’s privacy considerations
  • RA-03 — Risk Assessment: produces the risk assessments that drive asset prioritization within the critical infrastructure protection plan
  • SI-12 — Information Management and Retention: governs how information related to critical infrastructure protection is managed and retained over time

Frequently asked questions

What is NIST SP 800-53 PM-08?

PM-08 is the NIST SP 800-53 control that requires organizations to develop and maintain a critical infrastructure and key resources protection plan. The plan must address both information security and privacy issues, align with applicable laws and directives such as HSPD 7, and reflect a prioritization strategy for the organization’s most important assets. It sits within the Program Management family and applies to the PRIVACY baseline.

What happens if PM-08 is not implemented?

Without a critical infrastructure and key resources protection plan, your organization lacks a documented strategy for identifying and protecting its most important assets. Auditors will flag the absence of this plan as a program-level deficiency, which can lead to findings during certification assessments or regulatory reviews. The gap also means your protection efforts aren’t aligned with national infrastructure protection frameworks like the National Infrastructure Protection Plan.

How do you audit PM-08?

Auditing PM-08 starts with verifying that a critical infrastructure and key resources protection plan exists and has been updated within its defined review cycle. Assessors examine whether the plan addresses both information security and privacy issues, references applicable directives including HSPD 7, and documents asset prioritization criteria. They also review supporting evidence such as the information security program plan, privacy program plan, and procedures for developing and updating the protection plan.

What is a critical infrastructure protection plan?

A critical infrastructure protection plan is a documented strategy that identifies an organization’s critical infrastructure and key resources and defines how those assets will be protected. The plan draws on requirements from laws, executive orders, regulations, and standards to establish protection strategies based on asset prioritization. For organizations subject to NIST SP 800-53, this plan must cover both information security and privacy considerations and align with frameworks like the National Infrastructure Protection Plan.

Experience superior visibility and a simpler approach to cyber risk management