Cybersecurity program management covers the oversight structures, audit processes, and governance mechanisms that ensure a security program operates as intended at an organizational level. It addresses how policies are maintained, how audits are verified, and how leadership accountability is defined within frameworks like NIST 800-53.
Security Program Management
One of my favorite books growing up was a Dr. Seuss book, and in it they had a bee, and they wanted to make sure that this bee was doing their job. So they hired somebody to watch the bee. But they weren't sure if the watcher was going to watch the bee or not, and whether they were going to follow through with their job, so they hired somebody to watch the bee watcher. And then they hired a watcher to watch the bee watcher watcher, and it kept going.
Anyways, the point being, that's kind of what the security program is: we need to watch the watcher, we need to watch overall what is happening.
Here are all of our operational functions that we carry out to make sure that we have a robust security program, but there is kind of this overall scoping theme of what does our cybersecurity program look like, and how are we going to manage it all from an upper level.
In other lessons I've laid out how we are going to create policies, and then from those policies we're going to create procedures, guidelines and controls in order to reinforce those policies. But the thing is, we have these policies: who's going to audit those policies? How are they going to be updated? How often are we going to update that? The thing is that we need to take a look at these policies, and we need to update these policies and do certain maintenance tasks on these policies as well.
Let's look at it from a little different angle here. Let's say we have an audit that we do on a yearly basis, and we're going to audit maybe our accounts. We're going to go through and make sure that anybody that's left the company, their account is in fact deprovisioned and turned off, as well as anybody who's changed positions has the proper security control and the certain access that they need to have. So we're going to perform these audits on the accounts.
The thing is that this is just one audit of many audits that we're going to do to make sure that everything is getting done. But how do we know that all of the audits are going to get done? So what we have is an audit to check all of the audits, to make sure that this has happened this year, before we get into the point where we're going to be audited from the SOC auditors, that we go through and check and say, yeah, all of these audits are in fact done.
This is just one example of program management, of how we're going to manage the program and our audits to verify that everything has gotten done that needs to get done.
Let me give you a brief glimpse into another aspect of this. What I have here is all of the controls that are set up for the NIST 800-53 framework, which is what this course has been modeled after. Here we have the different control families, so this is one control family, and I scroll down, this is another control family. These are the areas that are the control families, and once again, that I've modeled all of these different functions off of.
If you look at the beginning one of each one of these, so here's CA1, the first thing that it approaches is the policies and procedures. These are the policies and procedures that are set out to monitor and control the rest of these policies and procedures, and we see that for this family as well: policies and procedures, and we're going to develop, document and disseminate. Then it has some information we need to fill in. There's a lot more to this, I'm not showing everything here, so there's a lot more to each one of these controls, but I just want you to see how each one of these policies, this would be a set of policies, are governed by this first policy here.
Not only that, but they have a full family here, a whole category that's devoted towards program, security program plan and management. So it talks about the leadership roles and what the leadership roles look like, and some other overall kind of scoping themes to what this program management looks like for the overall program.
Overall, this is just that final last check to make sure that things are being managed in a way that they need to be managed at.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →