{"data":{"id":"PM-13","name":"Security and Privacy Workforce","family":"PM","family_name":"Program Management","withdrawn":false,"description":"Establish a security and privacy workforce development and improvement program.","supplemental_guidance":"Security and privacy workforce development and improvement programs include defining the knowledge, skills, and abilities needed to perform security and privacy duties and tasks; developing role-based training programs for individuals assigned security and privacy roles and responsibilities; and providing standards and guidelines for measuring and building individual qualifications for incumbents and applicants for security- and privacy-related positions. Such workforce development and improvement programs can also include security and privacy career paths to encourage security and privacy professionals to advance in the field and fill positions with greater responsibility. The programs encourage organizations to fill security- and privacy-related positions with qualified personnel. Security and privacy workforce development and improvement programs are complementary to organizational security awareness and training programs and focus on developing and institutionalizing the core security and privacy capabilities of personnel needed to protect organizational operations, assets, and individuals.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"PM-13","name":"Security and Privacy Workforce","description":"Establish a security and privacy workforce development and improvement program.","discussion":"Security and privacy workforce development and improvement programs include defining the knowledge, skills, and abilities needed to perform security and privacy duties and tasks; developing role-based training programs for individuals assigned security and privacy roles and responsibilities; and providing standards and guidelines for measuring and building individual qualifications for incumbents and applicants for security- and privacy-related positions. Such workforce development and improvement programs can also include security and privacy career paths to encourage security and privacy professionals to advance in the field and fill positions with greater responsibility. The programs encourage organizations to fill security- and privacy-related positions with qualified personnel. Security and privacy workforce development and improvement programs are complementary to organizational security awareness and training programs and focus on developing and institutionalizing the core security and privacy capabilities of personnel needed to protect organizational operations, assets, and individuals.","related_controls":["AT-02","AT-03"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Information Security Workforce' to 'Security and Privacy Workforce'. Privacy added."}},"compliance_mappings":{"iso_27001_2022":["5.1","7.2","7.3","A.5.4","A.6.3"],"iso_27002_2022":["5.4","6.3"],"cobit_2019":["APO07","BAI08","EDM04"],"pci_dss_v4":[],"nist_csf_2":["GV.RR-01","GV.RR-02","GV.RR-03","GV.RR-04","PR.AT-01","PR.AT-02"],"cis_controls_v8":["CIS 14","CIS 14.1","CIS 14.9"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(g)"],"apra_cps_234":["Para 15","Para 19-20"],"mas_trm":[],"pra_op_resilience":["SS1/21-5.1","SS2/21-17.1"],"bsi_grundschutz":["ORP.2","ORP.3"],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["5.4","6.3"],"rbi_csf":["ITGRCA.24"],"fisc":[],"lgpd_bcb":["BCB.Art.4"],"hkma_tme1":["TME1.7.1"],"mlps_2":["8.1.7.1"],"dnb_good_practice":["DNB.8.2","DNB.8.3","DNB.9.2"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-3"],"cbuae":["CR-1","CR-11"],"nca_ecc":["1-2","1-4","1-10"],"qatar_nia":["GV"],"sama_csf":["1.6"],"uae_ia":["T1","T5"],"bog_cisd":["CISD-II","CISD-XV"],"bom_ctrm":["1.1","1.2","3.8"],"cbe_csf":["GOV-1","GOV-2","GOV-4"],"cbn_csf":["Part1.1","Part8"],"sa_js2":["JS2-4","JS2-8.6"],"bcbs_239":["Principle 1"],"bot_cyber":["Ch1.1","Ch7.1"],"cpmi_pfmi":["CG.GOV","PFMI.P2"],"eba_ict":["3.4.7"],"ecb_croe":["CROE.2.1.1","CROE.2.1.2"],"ffiec_is":["I.A","I.B","I.C","II.C.7(e)"],"hipaa_sr":["§164.308(a)(5)(i)","§164.308(a)(5)(ii)(A)"],"iosco_cyber":["GOV-2","GOV-4"],"nydfs_500":["500.4","500.10"],"sebi_cscrf":["CAPACITY","GV.RR","PR.AT"],"cmmc_2":["AT"],"nerc_cip":[],"nrc_73_54":["RG5.71-C-AT"],"tsa_psd":["SD-2 Sec H"],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["WORKFORCE"],"api_1164":[],"awia":["AWWA Sec 8"],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.5.1","SYSC 13.6.1"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["02.b"],"iso_27799":["7.2"],"lloyds_ms":["MS8.13"],"naic_ds":["4-personnel","4-training","4C"],"nhs_dspt":["NDG-2.1","NDG-3.1","NDG-3.2"],"pra_ss1_23":["P2.1"],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings extracted from framework-coverage data 2026-10-03: privacy baseline added, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-018","SP-043"]}}