# Security & Privacy Program Management: From Governance to Assurance Course

Canonical URL: <https://www.graduateschool.edu/courses/security-and-privacy-program-management>

## Overview

Most training treats security and privacy as two separate disciplines taught by two separate teams. This course treats them as one program, which is how they are actually funded, staffed and held accountable in a federal agency, and why the person running both under one budget is exactly who this is for. That framing pays off immediately: participants work with privacy risk arising from authorized processing rather than only from breaches, and set predictability, manageability and disassociability alongside confidentiality, integrity and availability. The governance module separates the statutory responsibilities of the CISO and the Senior Agency Official for Privacy relative to the CIO and agency head, which is exactly where accountability tends to blur in practice.

The course is built around judgment rather than recall. Participants tailor a control baseline and then identify tailoring that will not survive oversight, evaluate whether evidence is sufficient, current, relevant and objective, and test whether a metric is actionable and resistant to manipulation, rejecting activity-only measures. One module follows information across its whole lifecycle and asks participants to find data held without a current authorized purpose, and the closing workshop asks for a leadership risk briefing supporting one decision, then requires the participant to defend it against an objection. This is a program-accountability course rather than a technical one, written for people responsible for a program across an organization rather than for a single system. It pairs naturally with the [Privacy Act and PII/PHI Protection Course](https://www.graduateschool.edu/courses/privacy-act-and-pii-phi-protection), which teaches an employee to handle personal information correctly, while this one teaches the person accountable for the whole program.

## What you'll learn

- Distinguish program management from system-level operations, and cybersecurity risk from privacy risk
- Select a governance structure and define decision rights, escalation paths, and who may accept risk
- Separate the statutory responsibilities of the CISO and the Senior Agency Official for Privacy from those of the CIO and agency head
- Build a program strategy, multi-year roadmap and resource estimate tied to mission outcomes
- Categorize a system using FIPS 199 and explain how categorization drives baseline selection
- Map information flows across the lifecycle, apply data minimization, and determine when a Privacy Impact Assessment is required
- Select and tailor a control baseline, and justify tailoring in risk terms that survive oversight
- Evaluate assessment evidence, document findings, and track remediation through POA&Ms
- Integrate security and privacy into each phase of the system development lifecycle
- Design a monitoring strategy, and distinguish actionable metrics from activity-only measures
- Determine when an incident is a PII breach and what reporting obligations follow
- Deliver and defend a leadership risk briefing framed around a decision

## Curriculum

#### Module 1

- Two Missions, One Program: Security & Privacy Foundations
- Program management versus system operations
- Cybersecurity risk versus privacy risk including risk from authorized processing
- Shared and distinct objectives
- Confidentiality, integrity and availability related to predictability, manageability and disassociability
- The federal program authorities

#### Module 2

- Who Owns the Risk? Governance, Roles & Accountability
- Centralized, federated and hybrid governance
- Responsibilities at executive, program, system and control levels
- Authorizing official, risk executive, system owner, control owner and program manager
- CISO and SAOP statutory responsibilities
- Decision rights and escalation
- Risk appetite versus tolerance

#### Module 3

- Build the Program: Strategy, Policy & Planning
- Linking activities to mission outcomes
- Translating drivers into traceable requirements
- Policy, standard, procedure and guideline
- Multi-year roadmap
- Measurable objectives with owners
- Staffing, skills, funding and tooling estimates
- Role-based training
- Records evidencing governance decisions

#### Module 4

- Know the Risk: Security & Privacy Risk Management
- Framing risk context
- Threats, vulnerabilities, predisposing conditions and problematic data actions
- Assessing security risk and privacy impact on individuals
- Inherent versus residual risk
- FIPS 199 categorization
- Prioritizing against mission
- Selecting and approving responses
- The risk register

#### Module 5

- Follow the Data: Privacy Risk & Information Lifecycle
- PII versus sensitive PII and how aggregation changes sensitivity
- Mapping flows from collection to disposal
- Data minimization and data held without a current purpose
- Documented purpose and legal authority
- Notice, access, amendment and consent including SORNs
- When a Privacy Impact Assessment is required
- Retention and sanitization

#### Module 6

- Controls Make It Real: Security & Privacy Controls
- Controls as operationalized risk decisions
- Navigating the SP 800-53 catalog including privacy controls
- Organization-level versus system-level
- Common, system-specific and hybrid
- Baseline selection and tailoring through scoping, compensating controls and parameters
- Documenting in a system security and privacy plan

#### Module 7

- Prove It Works: Assessment, Compliance & Assurance
- Implementation versus effectiveness, compliance versus assurance
- Assessment scope, procedures and determination statements
- Examine, interview and test
- Judging evidence sufficiency
- Findings stating condition, criteria, cause and risk
- POA&Ms
- How results inform authorization and ongoing authorization

#### Module 8

- Privacy by Design, Security by Design
- Integrating into each SDLC phase
- Testable design-phase requirements
- Least privilege, least functionality, separation of duties and defense in depth in design review
- Minimization and purpose limitation in architecture
- Assessing privacy risk before implementation
- Change management
- Influencing engineering and acquisition early

#### Module 9

- Keep Watch: Monitoring, Metrics & Program Improvement
- Monitoring strategy and frequencies driven by volatility, impact level and risk
- KPIs versus KRIs
- Testing whether a metric is actionable and manipulation-resistant
- Tracking vulnerabilities, incidents, findings and corrective actions
- Reporting in mission language framed around a decision

#### Module 10

- When Things Change: Incidents, Third Parties & Emerging Risk
- Security and privacy roles across the incident lifecycle
- Determining when an incident is a PII breach and the reporting obligations
- Third-party and supply chain risk across the acquisition lifecycle
- Contract terms for security, privacy, incident reporting and assessment rights
- Evaluating emerging technology including AI
- When change requires reassessment, reauthorization or an updated PIA

#### Module 11

- From Program Manager to Advisor: Security & Privacy Workshop
- Evaluate a fictional federal organization, diagnose governance and accountability gaps separating root causes from symptoms, rank risks with rationale, locate ineffective control coverage, prioritize corrective actions by risk reduction against cost, and deliver and defend a leadership briefing

## Schedule
- Jan 26, 2027 – Jan 27, 2027 — Live Online
- Feb 5, 2027 – Feb 8, 2027 — Live Online
- Mar 12, 2027 – Mar 15, 2027 — Live Online
- Apr 27, 2027 – Apr 28, 2027 — Live Online
- May 26, 2027 – May 27, 2027 — Live Online
- Jun 17, 2027 – Jun 18, 2027 — Live Online
- Jul 26, 2027 – Jul 27, 2027 — Live Online
- Aug 3, 2027 – Aug 4, 2027 — Live Online

## Pricing

**Tuition:** $1049
