Skip to main content
Category: Security Controls & Tailoring

Program Management (PM) Controls

Also known as: PM, PM Control Family, Program Management Control Family
Simply put

Program Management (PM) controls are a set of safeguards in the NIST security and privacy controls catalog that focus on how an organization runs and oversees its overall cybersecurity program, rather than on protecting a single information system. They address organization-wide activities such as who manages the security program and how it operates. Because they cover the broader program, they are generally implemented at the enterprise level instead of on individual systems.

Formal definition

In NIST SP 800-53 Rev. 5, the Program Management (PM) family comprises controls addressing the establishment, oversight, and operation of an organization-wide information security and privacy program. These controls are typically deployed at the organizational level and are generally not associated with the impact-based control baselines applied to individual information systems, since they support governance functions rather than system-specific protections. Practitioners should verify the current set of PM controls and their applicability against the applicable revision and any agency-specific tailoring, as control content and organizational implementation guidance may vary. This entry does not cover project-management disciplines (such as schedule or cost controls) that share the 'program management' terminology but fall outside the NIST security and privacy control context.

Why it matters

Most control families in the NIST catalog answer the question of how a specific information system is protected. The Program Management (PM) family answers a different and often overlooked question: how the organization runs its overall security and privacy program. Without a functioning enterprise-level program, individual system controls tend to be implemented inconsistently, monitored unevenly, and disconnected from organizational risk decisions. PM controls provide the governance scaffolding, who is accountable for the program and how it operates, that gives system-level safeguards their coherence and authority.

Because PM controls are generally implemented at the enterprise level rather than on individual systems, they are typically not tied to the impact-based control baselines (low, moderate, high) applied when authorizing a specific system. This distinction matters in practice: an assessor reviewing a single system's implementation may not directly evaluate the PM family, yet weaknesses in program governance can undermine every system the organization operates. A common expert correction here is to remember that satisfying system-level controls does not demonstrate that an organization-wide program actually exists or functions, assessment of a system is not the same as assurance of the program behind it.

Readers should also note that the specific set of PM controls and their applicability can change across revisions of NIST SP 800-53 and may be further shaped by agency-specific tailoring. The governance emphasis of the family means its content is closely bound to how a given organization defines roles, responsibilities, and program operations, so the authoritative text and any applicable agency supplement should be verified rather than assumed.

Who it's relevant to

Chief Information Security Officers and Program Leaders
Those accountable for the organization-wide security and privacy program are the primary owners of PM controls, since the family focuses on who manages the program and how it operates. They should treat these controls as enterprise governance obligations distinct from the system-level safeguards their teams implement, and verify the current PM control set against the applicable SP 800-53 revision and any agency tailoring.
Information System Security Managers and System Owners
Practitioners responsible for individual systems should understand that PM controls generally live at the organizational level and are typically not part of the impact-based baseline applied to their system. Recognizing this boundary helps avoid the mistake of assuming that satisfying system-level controls demonstrates a functioning enterprise program; the two are related but separate.
Assessors and Auditors
Those evaluating compliance should distinguish assessment of a single system from assurance about the program that governs it. Because PM controls address program governance rather than system-specific protections, they may fall outside a system-focused assessment scope and should be examined against the current authoritative text and organizational implementation guidance rather than assumed.
Authorizing Officials and Governance Stakeholders
Officials making risk-based authorization decisions rely on the program-level foundation that PM controls describe. A sound enterprise program provides context for individual authorizations, but readers should confirm how their organization has defined and implemented the family, as content and applicability can vary across revisions and agency-specific tailoring.

Inside PM

PM Control Family
The Program Management family is a control set within NIST SP 800-53 that addresses organization-wide, enterprise-level security and privacy program management activities rather than the security of an individual information system. Practitioners should confirm the specific controls and identifiers against the applicable revision of NIST SP 800-53, as content and numbering can change across revisions.
Organization-Level Scope
Unlike most 800-53 control families that are selected and implemented per system as part of a security control baseline, PM controls generally apply across the organization and are typically implemented independently of any single system's impact level. They are commonly deployed program-wide to support the overall security and privacy program.
Not Part of the Baselines
PM controls are generally not included in the low, moderate, or high control baselines that are tailored for individual systems. Instead, they are intended to be implemented at the organizational level. Readers should verify how a given agency or authorizing official expects PM controls to be documented and assessed, as tailoring practices vary.
Program Governance Emphasis
The family is oriented toward governance and management functions, such as establishing and maintaining a security and privacy program, allocating resources, and providing enterprise oversight, that enable the effective implementation of system-specific controls in the other families. Specific control objectives should be confirmed against the current authoritative text.

Common questions

Answers to the questions practitioners most commonly ask about PM.

Are Program Management (PM) controls selected as part of a system's tailored control baseline like the technical and operational controls?
No. This is a common misconception. In NIST SP 800-53, the PM control family is generally described as being independent of any individual information system's control baseline. PM controls are typically implemented at the organization level to support the overall information security program, rather than being selected through the impact-level baseline (low, moderate, high) tailoring process applied to system-specific controls. Because they are organization-wide, they are generally deployed once and inherited by systems rather than reassessed system by system. You should verify the specific treatment of the PM family against the applicable revision of SP 800-53, as the family's structure and placement have evolved across revisions.
Does implementing the PM controls mean my organization is secure or fully compliant?
No. Implementing PM controls establishes and documents an information security program framework, but implementation is not the same as security, and it is not the same as authorization. PM controls generally address program governance elements such as security program planning, resource allocation, and risk management strategy, but they do not by themselves protect any given system, nor do they substitute for the assessment and authorization of individual systems. An expert would insist on distinguishing having a documented program from demonstrating that the program is effective and that individual systems remain within acceptable risk as verified through assessment and continuous monitoring.
Who in the organization is typically responsible for implementing PM controls?
Because PM controls are generally organization-wide rather than system-specific, responsibility usually rests with senior leadership and program-level roles rather than an individual system owner or ISSM. Roles commonly associated with these controls include the senior agency information security officer (or equivalent) and organizational risk management functions. The exact assignment of responsibility depends on your organization's structure and governance model, and you should confirm role designations against your organization's policies and the applicable authoritative guidance, since role terminology can differ across federal civilian, defense, and other environments.
How do PM controls relate to the Risk Management Framework (RMF) process for individual systems?
PM controls generally provide the organizational context and governance structure within which the RMF steps for individual systems are carried out, such as establishing a risk management strategy and information security program plan. System-level RMF activities, categorization, control selection, implementation, assessment, authorization, and continuous monitoring, typically operate against system-specific controls, while PM controls support those activities from the program level. The precise interaction should be confirmed against the current RMF guidance and the applicable revision of SP 800-53, as both continue to be updated.
Can systems inherit PM controls as common controls?
In most implementations, PM controls are treated as organization-wide and are candidates for inheritance as common controls, meaning individual systems can rely on the organizational implementation rather than duplicating it. Documenting this inheritance clearly is important so that assessors and authorizing officials understand which controls are provided at the program level. Confirm how your organization designates common controls and how inheritance is documented, since practices vary and must align with your governing guidance and applicable revision.
How is the effectiveness of PM controls evaluated, given they are not tied to a single system?
Because PM controls are program-level, their evaluation is generally handled at the organizational rather than the individual-system scope. Assessment approaches vary by organization and by the applicable guidance, and evaluating a documented program is distinct from confirming that it operates effectively over time. You should treat program-level assessment as separate from system authorization and verify the expected evaluation approach against current authoritative sources, since specific assessment methods and expectations may differ by agency and revision.

Common misconceptions

PM controls are selected and assessed per system like the other NIST SP 800-53 control families.
PM controls are generally intended for organization-level implementation and are not part of the system-specific low, moderate, or high baselines. They are typically managed program-wide, though agencies may specify how they are documented and assessed. Verify the expected approach with your authorizing official and the applicable revision.
Because PM controls are organizational, they can be treated as one-time or optional program paperwork.
Program management activities are ongoing governance functions that support the broader security and privacy program. Treating them as a one-time exercise misaligns with the continuous nature of program management; confirm current expectations against the applicable NIST SP 800-53 revision and agency guidance.
The PM family is unique to a single framework or authorization program.
The PM family is defined within NIST SP 800-53, which is maintained by NIST. How other frameworks or programs reference or incorporate it can differ, so do not assume it applies identically across FISMA, FedRAMP, or DoD RMF contexts without checking each program's authoritative guidance.

Best practices

Confirm the exact PM controls, identifiers, and objectives against the current applicable revision of NIST SP 800-53 rather than relying on memory, since control content can change across revisions.
Document PM controls at the organizational or program level and clearly distinguish them from system-specific control implementations to avoid duplicative or misplaced assessment.
Coordinate with your authorizing official to confirm how PM controls should be documented, implemented, and assessed, since tailoring and organizational expectations can vary.
Treat program management as an ongoing governance function integrated with your continuous monitoring efforts rather than a one-time documentation task.
Verify how PM controls are expected to be addressed within your specific compliance context (for example, FISMA, FedRAMP, or DoD RMF) rather than assuming uniform treatment across programs.