Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PM

PM-29Risk Management Program Leadership Roles

Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and Establish a Risk Executive (function) to view and analyze risk from an organization-wide perspective and ensure management of risk is consistent across the organization.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (8)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization8,680Leadership accountability for risk management makes missing authorization controls visible at the enterprise level and subject to remediation.
CWE-284Improper Access Control4,832Appointed accountable official aligns access control decisions with strategic risk processes, reducing systemic improper access control.
CWE-863Incorrect Authorization3,234Org-wide risk perspective ensures authorization logic is reviewed and corrected rather than implemented inconsistently per system.
CWE-269Improper Privilege Management2,907Senior risk management leadership and cross-org risk view enforce proper privilege management and prevent ad-hoc or inconsistent assignments.
CWE-732Incorrect Permission Assignment for Critical Resource1,824Risk Executive function drives correct permission assignment for critical resources by requiring risk analysis before granting broad access.
CWE-285Improper Authorization1,230Organization-level risk governance improves authorization consistency and prevents authorization decisions made without enterprise risk context.
CWE-250Execution with Unnecessary Privileges305Org-wide risk executive function provides accountability and oversight that directly reduces execution with unnecessary privileges through consistent identification and mitigation.
CWE-272Least Privilege Violation25Risk Executive role ensures least privilege is applied uniformly rather than left to individual system owners or projects.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PM

PM-1 PM-10 PM-11 PM-12 PM-13 PM-14 PM-15 PM-16 PM-17 PM-18 PM-19 PM-2 PM-20 PM-21 PM-22 PM-23 PM-24 PM-25 PM-26 PM-27 PM-28 PM-3 PM-30 PM-31 PM-32 PM-4 PM-5 PM-6 PM-7 PM-8 PM-9