PM-14 Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be
Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are d.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Organisational plans for security and privacy testing, training and monitoring activities · Policy repository / GRC workspace
- The process ensuring those plans are developed, maintained and executed as written · Policy repository / GRC workspace
- Evidence the plans continue to be executed, such as completion records against the planned schedule · Policy repository / GRC workspace
- Review record confirming the plans remain consistent with the organisational risk management strategy and priorities · Policy repository / GRC workspace
- Records of adjustment where risk priorities changed and the plans were revised to match · Policy repository / GRC workspace
First move
Common gaps auditors find
- Plans developed and then executed only in part, with no tracking that would surface the shortfall
- Testing, training and monitoring planned in separate silos with no consistency check across them
- Plans never re-tested against the risk management strategy, so activity continues on stale priorities
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-13 Security and Privacy Workforce. Establish a security and privacy workforce development and improvement program · PM-15 Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing security and privacy education and training for organizational personnel; To