SP 800-53A provides guidance on assessing controls in information security program plans, privacy program plans, system security plans, and privacy plans. Where the guidance refers to all plans listed above, the term “security and privacy plans” is used.

