Program Management (PM) Controls
Program Management (PM) controls are a set of safeguards in the NIST security and privacy controls catalog that focus on how an organization runs and oversees its overall cybersecurity program, rather than on protecting a single information system. They address organization-wide activities such as who manages the security program and how it operates. Because they cover the broader program, they are generally implemented at the enterprise level instead of on individual systems.
In NIST SP 800-53 Rev. 5, the Program Management (PM) family comprises controls addressing the establishment, oversight, and operation of an organization-wide information security and privacy program. These controls are typically deployed at the organizational level and are generally not associated with the impact-based control baselines applied to individual information systems, since they support governance functions rather than system-specific protections. Practitioners should verify the current set of PM controls and their applicability against the applicable revision and any agency-specific tailoring, as control content and organizational implementation guidance may vary. This entry does not cover project-management disciplines (such as schedule or cost controls) that share the 'program management' terminology but fall outside the NIST security and privacy control context.
Why it matters
Most control families in the NIST catalog answer the question of how a specific information system is protected. The Program Management (PM) family answers a different and often overlooked question: how the organization runs its overall security and privacy program. Without a functioning enterprise-level program, individual system controls tend to be implemented inconsistently, monitored unevenly, and disconnected from organizational risk decisions. PM controls provide the governance scaffolding, who is accountable for the program and how it operates, that gives system-level safeguards their coherence and authority.
Because PM controls are generally implemented at the enterprise level rather than on individual systems, they are typically not tied to the impact-based control baselines (low, moderate, high) applied when authorizing a specific system. This distinction matters in practice: an assessor reviewing a single system's implementation may not directly evaluate the PM family, yet weaknesses in program governance can undermine every system the organization operates. A common expert correction here is to remember that satisfying system-level controls does not demonstrate that an organization-wide program actually exists or functions, assessment of a system is not the same as assurance of the program behind it.
Readers should also note that the specific set of PM controls and their applicability can change across revisions of NIST SP 800-53 and may be further shaped by agency-specific tailoring. The governance emphasis of the family means its content is closely bound to how a given organization defines roles, responsibilities, and program operations, so the authoritative text and any applicable agency supplement should be verified rather than assumed.
Who it's relevant to
Inside PM
Common questions
Answers to the questions practitioners most commonly ask about PM.