Testing, Training, and Monitoring

LOW MODERATE HIGH
1 Overlay 7 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

    1. 1.Are developed and maintained; and
    2. 2.Continue to be executed; and
Discussion (NIST Supplemental Guidance)

A process for organization-wide security and privacy testing, training, and monitoring helps ensure that organizations provide oversight for testing, training, and monitoring activities and that those activities are coordinated. With the growing importance of continuous monitoring programs, the implementation of information security and privacy across the three levels of the risk management hierarchy and the widespread use of common controls, organizations coordinate and consolidate the testing and monitoring activities that are routinely conducted as part of ongoing assessments supporting a variety of controls. Security and privacy training activities, while focused on individual systems and specific roles, require coordination across all organizational elements. Testing, training, and monitoring plans and activities are informed by current threat and vulnerability assessments.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for PM-14 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. a process is implemented for ensuring that organizational plans for conducting security testing, training, and monitoring activities associated with organizational systems are developed;
  2. a process is implemented for ensuring that organizational plans for conducting security testing, training, and monitoring activities associated with organizational systems are maintained;
  3. a process is implemented for ensuring that organizational plans for conducting privacy testing, training, and monitoring activities associated with organizational systems are developed;
  4. a process is implemented for ensuring that organizational plans for conducting privacy testing, training, and monitoring activities associated with organizational systems are maintained;
  5. a process is implemented for ensuring that organizational plans for conducting security testing, training, and monitoring activities associated with organizational systems continue to be executed;
  6. a process is implemented for ensuring that organizational plans for conducting privacy testing, training, and monitoring activities associated with organizational systems continue to be executed;
  7. testing plans are reviewed for consistency with the organizational risk management strategy;
  8. training plans are reviewed for consistency with the organizational risk management strategy;
  9. monitoring plans are reviewed for consistency with the organizational risk management strategy;
  10. testing plans are reviewed for consistency with organization-wide priorities for risk response actions;
  11. training plans are reviewed for consistency with organization-wide priorities for risk response actions;
  12. monitoring plans are reviewed for consistency with organization-wide priorities for risk response actions.

Examine

[SELECT FROM: Information security program plan; privacy program plan; plans for conducting security and privacy testing, training, and monitoring activities; organizational procedures addressing the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities; risk management strategy; procedures for the review of plans for conducting security and privacy testing, training, and monitoring activities for consistency with risk management strategy and risk response priorities; results of risk assessments associated with conducting security and privacy testing, training, and monitoring activities; documentation of the timely execution of plans for conducting security and privacy testing, training, and monitoring activities; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibilities for developing and maintaining plans for conducting security and privacy testing, training, and monitoring activities; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Organizational processes for the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities; mechanisms supporting the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

Not applicable at this tier.

HIGH

  • Base control: Added (beyond standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for PM-14. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Information security program plan
  • privacy program plan
  • risk management strategy
  • procedures for the review of plans for conducting security and privacy testing, training, and monitoring activities for consistency with risk management strategy and risk response priorities

Testing

  • Organizational processes for the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities
  • mechanisms supporting the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities

Other Records

  • plans for conducting security and privacy testing, training, and monitoring activities
  • organizational procedures addressing the development and maintenance of plans for conducting security and privacy testing, training, and monitoring activities
  • results of risk assessments associated with conducting security and privacy testing, training, and monitoring activities
  • documentation of the timely execution of plans for conducting security and privacy testing, training, and monitoring activities
  • other relevant documents or records