Quick-reference card
| Field | Value |
|---|---|
| Control ID | PM-14 |
| Control Name | Testing, Training, and Monitoring |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Program Management |
| Baselines | PRIVACY |
| Relevance | Organization (First Party) |
| Risk Severity | Medium |
What this control requires
PM-14 requires organizations to coordinate security and privacy testing, training, and monitoring under a single oversight process aligned with their risk management strategy. Most organizations treat these three disciplines as separate workstreams, but PM-14 demands they operate under a single coordinating process with clear accountability.
In practice, this means you need documented plans for each activity that aren’t just written and shelved. Those plans must be actively executed on an ongoing basis, covering both security and privacy dimensions across all organizational systems. The NIST SP 800-53 framework treats this as a program management control because it sits above individual system boundaries.
The control also requires a review cycle. Testing, training, and monitoring plans must be evaluated for consistency with your organization’s risk management strategy and its priorities for risk response actions. Without that alignment, you can end up with a penetration testing schedule that doesn’t reflect your actual threat landscape or a training program that ignores the roles most exposed to current risks.
Why it matters
Organizations that lack a coordinated oversight process for testing, training, and monitoring create gaps auditors will find and adversaries can exploit. PM-14 exists because these three activities tend to drift apart over time, each managed by a different team with different priorities and different review cadences.
The result is a fragmented security posture that looks comprehensive on paper but fails under scrutiny. When testing plans aren’t reviewed against the risk management strategy, penetration tests may target the wrong systems. When training isn’t coordinated with monitoring findings, employees keep making the same mistakes that detection systems flag month after month. Audit teams evaluating your Program Management family controls will specifically look for evidence that these activities inform each other.
Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. For organizations subject to federal privacy requirements, the PRIVACY baseline designation means assessors will verify that privacy-specific testing and training aren’t treated as afterthoughts bolted onto security programs.
Where this breaks down most often is at the review step. Organizations develop initial plans but never revisit them as threat assessments change and organizational priorities shift. That disconnect between documented plans and actual risk posture is exactly what assessors and adversaries both look for.
Specifically, when security testing plans ignore current threat intelligence or training programs don’t reflect the information security awareness gaps that monitoring reveals, the entire coordination process that PM-14 mandates ceases to function. Assessors will trace the chain from risk assessment findings to plan updates to execution records, and missing links in that chain produce findings.
How to implement
For your organization
The most common failure mode is treating PM-14 as a documentation exercise rather than an operational coordination process. Organizations write plans, file them, and forget to connect them to the broader risk management strategy.
Establish a coordinating authority. Designate a role or team responsible for overseeing the integration of testing, training, and monitoring plans. This doesn’t require a new hire. It requires clear accountability for ensuring these three activities are planned together and reviewed against the same risk priorities.
Develop unified plans with execution timelines. Create documented plans for security testing, privacy testing, security training, privacy training, and continuous monitoring. Each plan should specify scope, frequency, responsible parties, and the systems covered. Align execution timelines so that training updates follow testing findings and monitoring configurations reflect both.
Build a review cadence tied to risk assessments. Review all plans at least annually, and trigger additional reviews when your risk management strategy changes, when new threat assessments are published, or when organizational priorities shift. The review should explicitly check that plan priorities match the current risk response hierarchy. Connecting your review process to continuous monitoring outputs helps keep plans grounded in actual findings.
Coordinate across organizational levels. PM-14 spans three tiers of the risk management hierarchy. System-level testing results should feed program-level decisions, and organization-wide priorities should inform system-level monitoring configurations. Role-based training programs should reflect what literacy training and awareness efforts identify as persistent gaps.
Produce and retain execution evidence. Document that plans aren’t just written but actively carried out. Maintain records of completed tests, delivered training sessions, and monitoring review meetings. Track changes to plans over time, showing that updates were driven by risk assessment findings.
Common mistakes to avoid:
- Creating separate, unlinked plans for security and privacy activities
- Reviewing plans on a fixed annual schedule without event-driven triggers
- Assigning plan oversight to a team that lacks visibility into all three activity areas
- Failing to document the rationale for plan changes when the risk strategy evolves
- Treating monitoring as a purely technical function disconnected from training and testing outcomes
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Program plans | Information security program plan and privacy program plan defining organizational scope, objectives, and resource allocation for testing, training, and monitoring |
| Activity-specific plans | Plans for conducting security and privacy testing (penetration tests, vulnerability assessments), training (role-based curricula, awareness programs), and monitoring (continuous monitoring strategy, tool configurations) |
| Procedures and policies | Organizational procedures addressing the development, maintenance, and review of testing, training, and monitoring plans, including approval workflows and update triggers |
| Risk alignment documentation | Risk management strategy and documented procedures for reviewing testing, training, and monitoring plans against risk response priorities and organizational threat assessments |
| Execution records | Documentation of completed testing cycles, delivered training sessions with attendance, and monitoring review meetings with action items and outcomes |
| Assessment results | Results of risk assessments used to inform and update testing scope, training curricula, and monitoring configurations across organizational systems |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 6.2 Terms and conditions of employment | Partial |
Related controls
- AT-02 — Literacy Training and Awareness: provides the foundational awareness training that PM-14 requires organizations to plan, execute, and review as part of the coordinated oversight process
- AT-03 — Role-Based Training: delivers specialized training for personnel in security and privacy roles, feeding into the training plans that PM-14 coordinates at the program level
- CA-07 — Continuous Monitoring: implements the system-level monitoring activities that PM-14 oversees and aligns with the organization’s risk management strategy
- CP-04 — Contingency Plan Testing: covers one category of security testing (disaster recovery and continuity) that PM-14 ensures is planned and executed consistently
- IR-03 — Incident Response Testing: validates incident response capabilities through exercises and drills, representing a testing activity that PM-14 coordinates alongside other testing plans
- PM-12 — Insider Threat Program: addresses a specific threat domain whose testing, training, and monitoring activities fall under the coordination umbrella that PM-14 establishes
- SI-04 — System Monitoring: defines the technical monitoring requirements at the system level that PM-14 ensures are planned, reviewed, and aligned with organizational risk priorities
Frequently asked questions
What is NIST SP 800-53 PM-14
PM-14 is the NIST SP 800-53 control that requires organizations to implement a coordinating process ensuring security and privacy testing, training, and monitoring plans are developed, maintained, executed, and reviewed against the risk management strategy. It sits in the Program Management family because it provides oversight across all organizational systems rather than governing a single system’s controls. The control applies at the organization level and carries a PRIVACY baseline designation.
What happens if PM-14 is not implemented
Without PM-14, testing, training, and monitoring activities operate in isolation, creating gaps that auditors will cite and adversaries can exploit. Privacy assessors will specifically look for coordinated privacy testing and training plans, and their absence can result in findings against the PRIVACY baseline. Organizations also lose the feedback loop where monitoring findings inform training updates and testing priorities, allowing known risks to persist across review cycles.
How do you audit PM-14
Auditors verify PM-14 by requesting the organization’s documented plans for security and privacy testing, training, and monitoring, then checking that those plans have been executed on schedule. They review evidence that plans were evaluated against the current risk management strategy and organization-wide risk response priorities, looking for documented review records with timestamps and rationale for any plan changes. They also confirm that both security and privacy dimensions are addressed across all twelve assessment objectives rather than treated as a single undifferentiated program.
What is the difference between PM-14 and CA-7
PM-14 is the program-level oversight process that ensures all testing, training, and monitoring plans are coordinated, maintained, and aligned with the organization’s risk management strategy. CA-7 is the system-level continuous monitoring control that defines how individual systems are monitored on an ongoing basis. PM-14 provides the organizational framework within which CA-7 activities are planned and reviewed, making CA-7 one of several activities that PM-14 coordinates.