STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

PM-14

Program ManagementRev 5organization

Testing, Training, and Monitoring

Baselines:Privacy

Control Statement

a. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: 1. Are developed and maintained; and 2. Continue to be executed; and b. Review testing, training, and monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

Supplemental Guidance

A process for organization-wide security and privacy testing, training, and monitoring helps ensure that organizations provide oversight for testing, training, and monitoring activities and that those activities are coordinated. With the growing importance of continuous monitoring programs, the implementation of information security and privacy across the three levels of the risk management hierarchy and the widespread use of common controls, organizations coordinate and consolidate the testing and monitoring activities that are routinely conducted as part of ongoing assessments supporting a variety of controls. Security and privacy training activities, while focused on individual systems and specific roles, require coordination across all organizational elements. Testing, training, and monitoring plans and activities are informed by current threat and vulnerability assessments.

Related Controls (7)

AT-2AT-3CA-7CP-4IR-3PM-12SI-4

CCI Identifiers (21)

CCI-003002Implement a process for ensuring that organizational plans for conducting security monitoring activities associated with organizational systems are developed.CCI-003003Implement a process for ensuring that organizational plans for conducting security monitoring activities associated with organizational systems are maintained.CCI-003004Implement a process for ensuring that organizational plans for conducting security testing associated with organizational systems continue to be executed.CCI-003005Implement a process for ensuring that organizational plans for conducting security training associated with organizational systems continue to be executed.CCI-003006Implement a process for ensuring that organizational plans for conducting security monitoring activities associated with organizational systems continue to be executed.CCI-002998Implement a process for ensuring that organizational plans for conducting security testing activities associated with organizational systems are developed.CCI-004353Implement a process for ensuring that organizational plans for conducting privacy testing activities associated with organizational systems are developed.

Linked STIG Checks (1)

Across 1 STIGs. Click to expand.

CCI-004354
Implement a process for ensuring that organizational plans for conducting privacy testing activities associated with organizational systems are maintained.
CCI-002999Implement a process for ensuring that organizational plans for conducting security testing activities associated with organizational systems are maintained.
CCI-003000Implement a process for ensuring that organizational plans for conducting security training activities associated with organizational systems are developed.
CCI-003001Implement a process for ensuring that organizational plans for conducting security training activities associated with organizational systems are maintained.
CCI-003007Review testing plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
CCI-003008Review training plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
CCI-003009Review monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.
CCI-004355Implement a process for ensuring that organizational plans for conducting privacy training activities associated with organizational systems are developed.
CCI-004356Implement a process for ensuring that organizational plans for conducting privacy training activities associated with organizational systems are maintained.
CCI-004357Implement a process for ensuring that organizational plans for conducting privacy monitoring activities associated with organizational systems are developed.
CCI-004358Implement a process for ensuring that organizational plans for conducting privacy monitoring activities associated with organizational information systems are maintained.
CCI-004359Implement a process for ensuring that organizational plans for conducting privacy testing associated with organizational systems continue to be executed.
CCI-004360Implement a process for ensuring that organizational plans for conducting privacy training associated with organizational systems continue to be executed.
CCI-004361Implement a process for ensuring that organizational plans for conducting privacy monitoring activities associated with organizational systems continue to be executed.