TechKnowSurge
NIST 800-53 PM-1 ISC2 CISSP 1.3 CompTIA Security+ 5.1 DoD 8140 OG-WRL-002 ISC2 CISSP 1.6 CompTIA SecurityX 1.2
VideoSecurityFree

Program Management

Cybersecurity program management covers the oversight structures, audit processes, and governance mechanisms that ensure a security program operates as intended at an organizational level. It addresses how policies are maintained, how audits are verified, and how leadership accountability is defined within frameworks like NIST 800-53.

Complete this video to capture a CTF flag worth 1 point.

About this video

A cybersecurity program is only as effective as the governance structure that monitors and maintains it. Beyond the day-to-day operational controls, organizations need a management layer responsible for ensuring that policies remain current, that procedures are followed, and that accountability is assigned at the leadership level. This is the domain of security program management — the oversight function that watches everything else. Without it, policies go unreviewed, audits go uncompleted, and gaps accumulate undetected. Audit management is a clear example of why this layer matters. Individual audits — such as annual reviews of user accounts to confirm deprovisioning and access changes — are necessary but insufficient on their own. Organizations must also conduct a higher-level audit of audits, confirming that every required review has been completed before external assessors, such as SOC auditors, arrive. This meta-level oversight ensures nothing falls through the cracks simply because no one was tracking whether it happened. NIST 800-53 formalizes this approach through dedicated control families for program management. Each control family begins with a policies-and-procedures control that governs everything beneath it, and a separate program management family addresses organization-wide concerns including leadership roles, program scope, and strategic accountability. This structure reflects a core principle of sound security governance: every operational function needs a corresponding oversight mechanism, and the program as a whole requires the same disciplined management applied to its individual parts.

What you'll learn

What's covered

Security Program Management

Aligned to

NIST 800-53
PM-1 Information Security Program Plan
ISC2 CISSP
1.3 Evaluate and apply security governance principles
1.6 Develop, document, and implement security policy, standards, procedures, and guidelines
CompTIA Security+
5.1 Summarize elements of effective security governance
DoD 8140
OG-WRL-002 Security Manager
CompTIA SecurityX
1.2 Given a scenario, implement the appropriate risk management strategies, policies, and controls

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Access Control
A security mechanism that restricts access to resources based on policies, roles, or identity.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
NIST 800-53
A NIST Special Publication that provides a comprehensive catalog of security and privacy controls for federal information systems, organized into control families such as access control, audit, and incident response. It is widely adopted beyond the federal sector as a baseline for security programs.
Control Family
A grouping of related security controls within the NIST 800-53 framework that address a common security topic or functional area.
Cybersecurity Program Management
The overarching coordination of people, budgets, roles, and resources across all security functions to ensure a unified and effective organizational security posture.
Audit
A formal and systematic examination of an organization's systems, policies, and procedures to verify that security controls are in place, functioning as intended, and meeting applicable compliance requirements.

Topics

Cybersecurity Governance Program Management Nist 800 53 Security Controls Security Audits Policy Management

Transcript

Watching the watcher

One of my favorite books growing up was a Dr. Seuss book, and in it they had a bee, and they wanted to make sure that this bee was doing their job. So they hired somebody to watch the bee. But they weren't sure if the watcher was going to watch the bee or not, and whether they were going to follow through with their job, so they hired somebody to watch the bee watcher. And then they hired a watcher to watch the bee watcher watcher, and it kept going.

Anyways, the point being, that's kind of what the security program is: we need to watch the watcher, we need to watch overall what is happening.

The scope above the operational functions

Here are all of our operational functions that we carry out to make sure that we have a robust security program, but there is kind of this overall scoping theme of what does our cybersecurity program look like, and how are we going to manage it all from an upper level.

In other lessons I've laid out how we are going to create policies, and then from those policies we're going to create procedures, guidelines and controls in order to reinforce those policies. But the thing is, we have these policies: who's going to audit those policies? How are they going to be updated? How often are we going to update that? The thing is that we need to take a look at these policies, and we need to update these policies and do certain maintenance tasks on these policies as well.

An audit of the audits

Let's look at it from a little different angle here. Let's say we have an audit that we do on a yearly basis, and we're going to audit maybe our accounts. We're going to go through and make sure that anybody that's left the company, their account is in fact deprovisioned and turned off, as well as anybody who's changed positions has the proper security control and the certain access that they need to have. So we're going to perform these audits on the accounts.

The thing is that this is just one audit of many audits that we're going to do to make sure that everything is getting done. But how do we know that all of the audits are going to get done? So what we have is an audit to check all of the audits, to make sure that this has happened this year, before we get into the point where we're going to be audited from the SOC auditors, that we go through and check and say, yeah, all of these audits are in fact done.

This is just one example of program management, of how we're going to manage the program and our audits to verify that everything has gotten done that needs to get done.

Program management in the NIST 800-53 controls

Let me give you a brief glimpse into another aspect of this. What I have here is all of the controls that are set up for the NIST 800-53 framework, which is what this course has been modeled after. Here we have the different control families, so this is one control family, and I scroll down, this is another control family. These are the areas that are the control families, and once again, that I've modeled all of these different functions off of.

If you look at the beginning one of each one of these, so here's CA1, the first thing that it approaches is the policies and procedures. These are the policies and procedures that are set out to monitor and control the rest of these policies and procedures, and we see that for this family as well: policies and procedures, and we're going to develop, document and disseminate. Then it has some information we need to fill in. There's a lot more to this, I'm not showing everything here, so there's a lot more to each one of these controls, but I just want you to see how each one of these policies, this would be a set of policies, are governed by this first policy here.

Not only that, but they have a full family here, a whole category that's devoted towards program, security program plan and management. So it talks about the leadership roles and what the leadership roles look like, and some other overall kind of scoping themes to what this program management looks like for the overall program.

Overall, this is just that final last check to make sure that things are being managed in a way that they need to be managed at.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →