Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PM

PM-14Testing, Training, and Monitoring

Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be executed; and Review testing, training, and monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-20Improper Input Validation13,143Security testing and developer training directly verify and enforce proper input validation, reducing exploitability of injection and malformed-data weaknesses.
CWE-352Cross-Site Request Forgery (CSRF)10,337Security testing regimens explicitly include checks for missing or ineffective anti-CSRF protections in web applications.
CWE-284Improper Access Control4,832Ongoing testing, training, and monitoring plans verify that access-control enforcement remains effective and aligned with risk priorities.
CWE-287Improper Authentication4,730Authentication testing and monitoring activities ensure mechanisms are implemented, maintained, and resistant to bypass.
CWE-693Protection Mechanism Failure476The control requires systematic testing and monitoring of protection mechanisms to confirm they function as intended against organizational risks.
CWE-778Insufficient Logging23Monitoring plans mandate sufficient logging and event collection to detect anomalous behavior and support incident response.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PM

PM-1 PM-10 PM-11 PM-12 PM-13 PM-15 PM-16 PM-17 PM-18 PM-19 PM-2 PM-20 PM-21 PM-22 PM-23 PM-24 PM-25 PM-26 PM-27 PM-28 PM-29 PM-3 PM-30 PM-31 PM-32 PM-4 PM-5 PM-6 PM-7 PM-8 PM-9