# Security & Privacy Program Management: From Governance to Assurance Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/security-and-privacy-program-management-self-paced>

## Overview

Security and privacy are usually taught as two disciplines by two teams. This course teaches them as one program, because that is how a federal agency actually funds, staffs and holds them accountable, and the buyer running both under a single budget is precisely the audience. The payoff shows up straight away: learners work with privacy risk that arises from authorized processing rather than only from breaches, and place predictability, manageability and disassociability alongside confidentiality, integrity and availability. The governance module pulls apart the statutory responsibilities of the CISO and the Senior Agency Official for Privacy against those of the CIO and agency head, which is the exact point where accountability blurs in practice.

Judgment matters more than recall throughout. Learners tailor a control baseline and then spot tailoring that oversight will reject, weigh whether evidence is sufficient, current, relevant and objective, and test a metric for whether it is actionable and manipulation-resistant, throwing out activity-only measures. One module traces information across its entire lifecycle and asks learners to locate data being held without a current authorized purpose, and the final workshop requires a leadership risk briefing built around a single decision, then requires the learner to defend it against an objection. The audience is senior: this is program accountability rather than engineering, aimed at people responsible for a program across an organization rather than for one system. It is a natural companion to the [Privacy Act and PII/PHI Protection Course](https://www.graduateschool.edu/courses/privacy-act-and-pii-phi-protection-self-paced), which teaches an individual employee to handle personal information correctly, while this course addresses the person accountable for the entire program.

## What you'll learn

- Distinguish program management from system-level operations, and cybersecurity risk from privacy risk
- Select a governance structure and define decision rights, escalation paths, and who may accept risk
- Separate the statutory responsibilities of the CISO and the Senior Agency Official for Privacy from those of the CIO and agency head
- Build a program strategy, multi-year roadmap and resource estimate tied to mission outcomes
- Categorize a system using FIPS 199 and explain how categorization drives baseline selection
- Map information flows across the lifecycle, apply data minimization, and determine when a Privacy Impact Assessment is required
- Select and tailor a control baseline, and justify tailoring in risk terms that survive oversight
- Evaluate assessment evidence, document findings, and track remediation through POA&Ms
- Integrate security and privacy into each phase of the system development lifecycle
- Design a monitoring strategy, and distinguish actionable metrics from activity-only measures
- Determine when an incident is a PII breach and what reporting obligations follow
- Deliver and defend a leadership risk briefing framed around a decision

## Prerequisites

Working familiarity with security and privacy fundamentals.

## Curriculum

#### Module 1

- Two Missions, One Program: Security & Privacy Foundations
- Program management versus system operations
- Cybersecurity risk versus privacy risk including risk from authorized processing
- Shared and distinct objectives
- Confidentiality, integrity and availability related to predictability, manageability and disassociability
- The federal program authorities

#### Module 2

- Who Owns the Risk? Governance, Roles & Accountability
- Centralized, federated and hybrid governance
- Responsibilities at executive, program, system and control levels
- Authorizing official, risk executive, system owner, control owner and program manager
- CISO and SAOP statutory responsibilities
- Decision rights and escalation
- Risk appetite versus tolerance

#### Module 3

- Build the Program: Strategy, Policy & Planning
- Linking activities to mission outcomes
- Translating drivers into traceable requirements
- Policy, standard, procedure and guideline
- Multi-year roadmap
- Measurable objectives with owners
- Staffing, skills, funding and tooling estimates
- Role-based training
- Records evidencing governance decisions

#### Module 4

- Know the Risk: Security & Privacy Risk Management
- Framing risk context
- Threats, vulnerabilities, predisposing conditions and problematic data actions
- Assessing security risk and privacy impact on individuals
- Inherent versus residual risk
- FIPS 199 categorization
- Prioritizing against mission
- Selecting and approving responses
- The risk register

#### Module 5

- Follow the Data: Privacy Risk & Information Lifecycle
- PII versus sensitive PII and how aggregation changes sensitivity
- Mapping flows from collection to disposal
- Data minimization and data held without a current purpose
- Documented purpose and legal authority
- Notice, access, amendment and consent including SORNs
- When a Privacy Impact Assessment is required
- Retention and sanitization

#### Module 6

- Controls Make It Real: Security & Privacy Controls
- Controls as operationalized risk decisions
- Navigating the SP 800-53 catalog including privacy controls
- Organization-level versus system-level
- Common, system-specific and hybrid
- Baseline selection and tailoring through scoping, compensating controls and parameters
- Documenting in a system security and privacy plan

#### Module 7

- Prove It Works: Assessment, Compliance & Assurance
- Implementation versus effectiveness, compliance versus assurance
- Assessment scope, procedures and determination statements
- Examine, interview and test
- Judging evidence sufficiency
- Findings stating condition, criteria, cause and risk
- POA&Ms
- How results inform authorization and ongoing authorization

#### Module 8

- Privacy by Design, Security by Design
- Integrating into each SDLC phase
- Testable design-phase requirements
- Least privilege, least functionality, separation of duties and defense in depth in design review
- Minimization and purpose limitation in architecture
- Assessing privacy risk before implementation
- Change management
- Influencing engineering and acquisition early

#### Module 9

- Keep Watch: Monitoring, Metrics & Program Improvement
- Monitoring strategy and frequencies driven by volatility, impact level and risk
- KPIs versus KRIs
- Testing whether a metric is actionable and manipulation-resistant
- Tracking vulnerabilities, incidents, findings and corrective actions
- Reporting in mission language framed around a decision

#### Module 10

- When Things Change: Incidents, Third Parties & Emerging Risk
- Security and privacy roles across the incident lifecycle
- Determining when an incident is a PII breach and the reporting obligations
- Third-party and supply chain risk across the acquisition lifecycle
- Contract terms for security, privacy, incident reporting and assessment rights
- Evaluating emerging technology including AI
- When change requires reassessment, reauthorization or an updated PIA

#### Module 11

- From Program Manager to Advisor: Security & Privacy Workshop
- Evaluate a fictional federal organization, diagnose governance and accountability gaps separating root causes from symptoms, rank risks with rationale, locate ineffective control coverage, prioritize corrective actions by risk reduction against cost, and deliver and defend a leadership briefing

## Pricing

**Tuition:** $1049
