Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PM-14 — Testing, Training, and Monitoring

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

0Enhancements
0Parameters
1Baseline memberships
3Assessment methods

PM — Program Management · NIST SP 800-53 Release 5.2.0

Privacy
Official NIST control content

Control statement

  1. a.Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems:
    1. 1.Are developed and maintained; and
    2. 2.Continue to be executed; and
  2. b.Review testing, training, and monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
Official NIST discussion

Discussion

A process for organization-wide security and privacy testing, training, and monitoring helps ensure that organizations provide oversight for testing, training, and monitoring activities and that those activities are coordinated. With the growing importance of continuous monitoring programs, the implementation of information security and privacy across the three levels of the risk management hierarchy and the widespread use of common controls, organizations coordinate and consolidate the testing and monitoring activities that are routinely conducted as part of ongoing assessments supporting a variety of controls. Security and privacy training activities, while focused on individual systems and specific roles, require coordination across all organizational elements. Testing, training, and monitoring plans and activities are informed by current threat and vulnerability assessments.

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Testing, Training, and Monitoring as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to enterprise program governance, accountability, resources, metrics, and organization-wide risk decisions.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • program charters and policies
  • governance meeting records
  • risk and performance metrics
  • resource and responsibility assignments

Common failure patterns

  • program metrics count activity instead of outcomes
  • system-level risks never reach enterprise governance
  • responsibilities assigned without authority or resources
  • privacy and security managed in separate silos

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PM-14a.
    1. PM-14a.01
      1. PM-14a.01[01]a process is implemented for ensuring that organizational plans for conducting security testing, training, and monitoring activities associated with organizational systems are developed;
      2. PM-14a.01[02]a process is implemented for ensuring that organizational plans for conducting security testing, training, and monitoring activities associated with organizational systems are maintained;
      3. PM-14a.01[03]a process is implemented for ensuring that organizational plans for conducting privacy testing, training, and monitoring activities associated with organizational systems are developed;
      4. PM-14a.01[04]a process is implemented for ensuring that organizational plans for conducting privacy testing, training, and monitoring activities associated with organizational systems are maintained;
    2. PM-14a.02
      1. PM-14a.02[01]a process is implemented for ensuring that organizational plans for conducting security testing, training, and monitoring activities associated with organizational systems continue to be executed;
      2. PM-14a.02[02]a process is implemented for ensuring that organizational plans for conducting privacy testing, training, and monitoring activities associated with organizational systems continue to be executed;
  2. PM-14b.
    1. PM-14b.[01]testing plans are reviewed for consistency with the organizational risk management strategy;
    2. PM-14b.[02]training plans are reviewed for consistency with the organizational risk management strategy;
    3. PM-14b.[03]monitoring plans are reviewed for consistency with the organizational risk management strategy;
    4. PM-14b.[04]testing plans are reviewed for consistency with organization-wide priorities for risk response actions;
    5. PM-14b.[05]training plans are reviewed for consistency with organization-wide priorities for risk response actions;
    6. PM-14b.[06]monitoring plans are reviewed for consistency with organization-wide priorities for risk response actions.

Examine

  • Information security program plan
  • privacy program plan
  • plans for conducting security and privacy testing, training, and monitoring activities
  • organizational procedures addressing the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities
  • risk management strategy
  • procedures for the review of plans for conducting security and privacy testing, training, and monitoring activities for consistency with risk management strategy and risk response priorities
  • results of risk assessments associated with conducting security and privacy testing, training, and monitoring activities
  • documentation of the timely execution of plans for conducting security and privacy testing, training, and monitoring activities
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for developing and maintaining plans for conducting security and privacy testing, training, and monitoring activities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities
  • mechanisms supporting the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Source record

Authoritative sources