Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PL

PL-6Security-related Activity Planning

Security-related Activity Planning

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-400Uncontrolled Resource Consumption3,324Planning and coordination of security activities (scans, tests, maintenance) directly imposes scheduling and throttling that prevents those activities from producing uncontrolled resource consumption.
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2,603Coordination of concurrent security activities reduces the probability that shared resources will be accessed simultaneously without proper synchronization.
CWE-770Allocation of Resources Without Limits or Throttling1,979Explicit planning of security-related actions requires defining limits, windows, and resource allocations, making allocation without throttling far less likely.
CWE-799Improper Control of Interaction Frequency67The control requires defining frequency, timing, and approval for security interactions, directly addressing uncontrolled interaction rates.
CWE-833Deadlock21Advance scheduling and deconfliction of security tasks lowers the chance that overlapping operations will produce deadlock conditions on shared resources.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PL

PL-1 PL-10 PL-11 PL-2 PL-3 PL-4 PL-5 PL-7 PL-8 PL-9