PM-13: Security and Privacy Workforce

PM-13 requires organizations to build and maintain a formal program that develops, improves, and sustains the security and privacy

Quick-reference card

FieldValue
Control IDPM-13
Control titleSecurity and Privacy Workforce
FrameworkNIST SP 800-53 Revision 5
Control familyProgram Management
BaselinesPRIVACY
Implementation levelOrganization
RelevanceFirst Party
Risk severityLow

What this control requires

PM-13 requires organizations to build and maintain a formal program that develops, improves, and sustains the security and privacy workforce. That means defining what your people need to know, training them based on their specific roles, and measuring whether they’re actually qualified to do the work you’ve assigned them.

In practice, this goes well beyond sending staff to an annual conference. You need documented knowledge, skills, and abilities (KSA) profiles for every security and privacy role. You need role-based training aligned to those profiles. And you need a defensible way to evaluate whether incumbents and new hires meet the bar, not just a checkbox confirming they attended a webinar.

The control also calls for career path structures that encourage security and privacy professionals to grow within the discipline. Without deliberate career planning, organizations lose institutional knowledge as experienced practitioners leave for roles that offer clearer advancement. PM-13 exists to treat workforce capability as a managed program, not a side effect of hiring.

Why it matters

Most organizations can point to a training budget, but few can produce a structured workforce development and improvement program that maps roles to required competencies and tracks progress over time. Auditors notice the difference.

Failure to maintain this control introduces audit risk during federal authorization processes, privacy impact assessments, and any engagement where an assessor asks how security roles are defined and staffed. Without documented KSA requirements tied to role-based training, you can’t demonstrate that the people protecting your systems are qualified to do so.

The risk compounds when staff turnover is high. An organization without a workforce development program has no repeatable method for onboarding replacements into security and privacy roles. Institutional knowledge walks out the door, and the gap between what a role demands and what the person filling it can deliver widens silently.

Regulatory frameworks beyond NIST SP 800-53 increasingly expect formalized workforce competency programs. ISO 27001 requires demonstrated competence for roles affecting information security. Privacy regulations demand that personnel handling personal data understand their obligations. PM-13 failures don’t trigger a single dramatic event. They create a slow erosion of capability that auditors, regulators, and attackers all eventually find.

What attackers exploit:

  • Undertrained staff who misconfigure access controls, firewall rules, or encryption settings because they lack role-specific technical training
  • Security teams without current knowledge of evolving tactics, techniques, and procedures (TTPs), making detection and response slower
  • Privacy personnel unfamiliar with regulatory requirements, leading to improper data handling that attackers leverage for social engineering
  • Gaps in incident response capability when the workforce development program doesn’t include tabletop exercises or simulated breach scenarios
  • Overreliance on a single subject matter expert whose departure leaves critical security functions unstaffed and undocumented

How to implement

For your organization

The most common failure with PM-13 isn’t that organizations skip workforce development entirely. It’s that they conflate general security awareness training with the role-based, competency-driven program this control requires. Awareness training tells everyone to watch for phishing. PM-13 demands that your incident responders, system administrators, privacy officers, and security architects each receive training calibrated to their specific duties.

Step 1: Define roles and KSA profiles. Inventory every position with security or privacy responsibilities. For each role, document the specific knowledge areas, skills, and abilities required. The NICE Cybersecurity Workforce Framework provides a structured taxonomy you can map to your organization’s roles rather than building from scratch.

Step 2: Assess current competency gaps. Compare existing staff qualifications against the KSA profiles. Use self-assessments, manager evaluations, and certification records to identify where gaps exist. Document these gaps as the baseline your program will address.

Step 3: Design role-based training programs. Build training plans that address identified gaps for each role category. Include a mix of formal coursework, hands-on labs, mentorship, and cross-training. Align training content to the specific systems, frameworks, and regulations your organization uses rather than relying solely on generic vendor courses.

Step 4: Establish qualification standards. Define measurable criteria for determining whether someone meets the competency bar for their role. This might include certifications, demonstrated skills through exercises, or documented experience thresholds. Apply these standards consistently to both incumbents and new hires.

Step 5: Build career progression paths. Map advancement opportunities within security and privacy functions so practitioners can see a trajectory from junior analyst to senior architect or from privacy analyst to chief privacy officer. Organizations that skip this step lose experienced staff to competitors offering clearer growth.

Step 6: Implement continuous measurement. Track training completion rates, qualification assessment results, time-to-competency for new hires, and retention rates for security and privacy staff. Review these metrics at least annually and adjust the program based on trends.

Common tooling categories: Learning management systems (LMS) for tracking completion, competency management platforms for mapping KSAs to roles, and cybersecurity range platforms for hands-on technical training.

Common mistakes to avoid: Treating a spreadsheet of completed certifications as a workforce development program. Failing to update KSA profiles when roles or technologies change. Applying identical training plans to roles with fundamentally different responsibilities.

Evidence examples

Evidence categoryExample artifactPurpose
Program charterSecurity and privacy workforce development and improvement program plan defining scope, objectives, roles covered, and governance structureDemonstrates the program exists as a managed, documented initiative
KSA role profilesRole-based knowledge, skills, and abilities matrix mapping each security and privacy position to required competenciesShows that workforce requirements are defined per role, not generic
Training curriculumRole-based training program documentation specifying courses, labs, and exercises aligned to each KSA profileProves training is tailored to role responsibilities
Qualification standardsMeasurable criteria and assessment procedures for evaluating whether incumbents and applicants meet role-specific competency thresholdsDemonstrates the organization evaluates, not just trains
Program proceduresDocumented procedures for onboarding, gap assessment, training delivery, and annual program reviewShows the program operates as a repeatable process
Program plan alignmentInformation security program plan and privacy program plan sections referencing workforce development objectives and integration pointsConfirms workforce development is embedded in broader security and privacy governance

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20226.3 Information security awareness, education and trainingPartial
ISO 27001:20227.2 Physical entryPartial
  • AT-02 — Literacy Training and Awareness: Covers the baseline security and privacy awareness training that all personnel receive, whereas PM-13 governs the broader workforce development program that defines role-based competencies, career paths, and qualification standards beyond general awareness.
  • AT-03 — Role-based Training: Addresses the delivery of training tailored to specific roles and responsibilities, serving as one component of the workforce development and improvement program that PM-13 requires organizations to establish and manage holistically.

Frequently asked questions

What is NIST SP 800-53 PM-13

PM-13 is the NIST SP 800-53 control that requires organizations to establish a security and privacy workforce development and improvement program. It covers defining role-based KSA profiles, delivering targeted training, setting qualification standards for incumbents and applicants, and building career paths that retain experienced practitioners.

What happens if PM-13 is not implemented

Without PM-13, an organization cannot demonstrate that its security and privacy workforce development and improvement program exists or functions. Auditors assessing federal systems will flag the absence of documented KSA requirements, role-based training programs, and qualification standards as a control gap. The practical consequence is staff whose skills don’t match their responsibilities, leading to misconfigurations, delayed incident response, and privacy handling errors that compound over time.

How do you audit PM-13

Auditing PM-13 means verifying that both a security workforce development and improvement program and a privacy workforce development and improvement program are established and operating. Assessors review the information security program plan and privacy program plan for workforce development references. They examine role-based training program documentation to confirm training is mapped to specific positions, and they evaluate qualification assessment records to determine whether the organization measures competency rather than attendance alone.

What is the difference between PM-13 and AT-3

PM-13 governs the overarching workforce development and improvement program, including role definitions, KSA profiles, career paths, and qualification standards for all security and privacy positions. AT-3 focuses specifically on delivering role-based training content to individuals assigned security and privacy responsibilities. PM-13 is the program that determines what training is needed and for whom. AT-3 is the execution of that training delivery. An organization can deliver role-based training without a formal workforce program, but PM-13 requires the program structure that makes AT-3 training systematic and measurable.


Learn more about the NIST SP 800-53 framework and how it structures security and privacy controls across federal and private-sector organizations.

Experience superior visibility and a simpler approach to cyber risk management