Program Management Plan
Documents how the organizational Program Management framework — Information Security Program Plan, Privacy Program Plan, Risk Management Strategy, Continuous Monitoring Strategy, POA&M process, system inventory, enterprise architecture, mission / business-process definition, insider-threat program, workforce program, testing / training / monitoring program, threat-awareness program, supply-chain-risk strategy, data governance, and complaint management — applies to this system. Covers the controls of the PM family in NIST SP 800-53 r5 and aligns with NIST SP 800-37 r2 (RMF), NIST SP 800-39 (Managing Information Security Risk), NIST SP 800-181 r1 (Workforce Framework), NIST IR 8062 (Privacy Risk Management Framework), and OMB Circular A-130 (Managing Information as a Strategic Resource). Note: PM controls are organizational rather than system-specific — most controls in this plan are documented as inherited from the organization's PM program with system-specific extensions where applicable.