Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PM

PM-2Information Security Program Leadership Role

Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832The appointed officer coordinates development and maintenance of access control policies and oversight across the enterprise.
CWE-269Improper Privilege Management2,907Dedicated senior leadership with resources directly enables consistent organization-wide privilege management and enforcement of least privilege.
CWE-285Improper Authorization1,230Centralized security program leadership ensures authorization rules and checks are defined, implemented, and sustained.
CWE-693Protection Mechanism Failure476Leadership and resources for the security program reduce the likelihood that protection mechanisms are missing, misconfigured, or neglected.
CWE-657Violation of Secure Design Principles19A senior officer with mission responsibility promotes adherence to secure design principles throughout the organization.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PM

PM-1 PM-10 PM-11 PM-12 PM-13 PM-14 PM-15 PM-16 PM-17 PM-18 PM-19 PM-20 PM-21 PM-22 PM-23 PM-24 PM-25 PM-26 PM-27 PM-28 PM-29 PM-3 PM-30 PM-31 PM-32 PM-4 PM-5 PM-6 PM-7 PM-8 PM-9