Security and Privacy Workforce
LOW MODERATE HIGHRequirements NIST SOURCE
Establish a security and privacy workforce development and improvement program.
Discussion (NIST Supplemental Guidance)
Security and privacy workforce development and improvement programs include defining the knowledge, skills, and abilities needed to perform security and privacy duties and tasks; developing role-based training programs for individuals assigned security and privacy roles and responsibilities; and providing standards and guidelines for measuring and building individual qualifications for incumbents and applicants for security- and privacy-related positions. Such workforce development and improvement programs can also include security and privacy career paths to encourage security and privacy professionals to advance in the field and fill positions with greater responsibility. The programs encourage organizations to fill security- and privacy-related positions with qualified personnel. Security and privacy workforce development and improvement programs are complementary to organizational security awareness and training programs and focus on developing and institutionalizing the core security and privacy capabilities of personnel needed to protect organizational operations, assets, and individuals.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PM-13 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- a security workforce development and improvement program is established;
- a privacy workforce development and improvement program is established.
Examine
[SELECT FROM: Information security program plan; privacy program plan; information security and privacy workforce development and improvement program documentation; procedures for the information security and privacy workforce development and improvement program; information security and privacy role-based training program documentation; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with information security and privacy program planning and plan implementation responsibilities; organizational personnel responsible for the information security and privacy workforce development and improvement program; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Organizational processes for implementing the information security and privacy workforce development and improvement program; mechanisms supporting and/or implementing the information security and privacy workforce development and improvement program].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PM-13. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Information security program plan
- privacy program plan
- information security and privacy workforce development and improvement program documentation
- procedures for the information security and privacy workforce development and improvement program
- information security and privacy role-based training program documentation
Testing
- Organizational processes for implementing the information security and privacy workforce development and improvement program
- mechanisms supporting and/or implementing the information security and privacy workforce development and improvement program
Other Records
- other relevant documents or records