Skip to content

Governance, Training & Secure Development

This template is the starting point for four practices your organization owns: executive sponsorship of the security program, the security investment review that follows from it, cybersecurity education and training, and the security and privacy work built into the software development lifecycle and the cloud-native architecture of the offering. These are governance, HR, and engineering practices. Fill in the sample sections with what your organization actually does, then keep the review outcomes recorded so the evidence matches the practice.

Quick Summary

A client-fillable template covering the executive support, security investment review, cybersecurity training, secure development lifecycle, and cloud-native architecture reviews the provider of the offering owns. It carries sample text you replace with your real practice, the KSI-PIY, KSI-CED, and KSI-CNA statements it answers, and a table of how the platform evidences each practice.

Customer-owned template

This is a starting-point template delivered with GRC-ITSM. The practices it describes are owned and executed by your organization, not by the platform. Fill the Organization-Defined Values, remove framework rows you are not pursuing, and adopt it as your own document before relying on it.

Related documentation

Download the KB article (Markdown)


Requirements this document answers

Key Security Indicators only. No FedRAMP Rule (FRR) in the 2026 Consolidated Rules names a governance, training, or secure development document; the obligation is the KSI outcome.

Policy and Inventory

KSI Name Statement
KSI-PIY-RES Reviewing Executive Support Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.
KSI-PIY-RIS Reviewing Investments in Security The effectiveness of the provider's investments in achieving security goals is persistently reviewed.
KSI-PIY-RSD Reviewing Security in the SDLC The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.

Related: KSI-CNA-IBP (Implementing Best Practices - "The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.") is answered by the Supply Chain Risk Template, which owns third-party resource configuration comparison.

Related: KSI-PIY-RVD (Reviewing Vulnerability Disclosures) is answered by the Vulnerability Disclosure Program Template, which owns the program's design, intake, and effectiveness review.

Cybersecurity Education

KSI Name Statement
KSI-CED-RAT Reviewing All Training The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

Cloud Native Architecture

KSI Name Statement
KSI-CNA-DFP Defining Functionality and Privileges The functionality and privileges for infrastructure and services are strictly defined.
KSI-CNA-MAT Minimizing Attack Surface Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.
KSI-CNA-OFA Optimizing for Availability Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.
KSI-CNA-RNT Restricting Network Traffic Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.
KSI-CNA-RVP Reviewing Protections The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.
KSI-CNA-ULN Using Logical Networking Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.
KSI-CNA-EIS Enforcing Intended State (no statement published in the 2026 Consolidated Rules)

Sample practice: executive support and security investment

Sample text. [Organization]'s security goals are set annually by [executive role] and endorsed by [governing body: security steering committee, executive leadership team, board committee]. The governing body meets [cadence], and its standing agenda covers progress against each goal, the security investments funded in the current period, and the outcomes those investments produced. Minutes record attendance, decisions, and the funding actions taken; they are the demonstration of executive support, not a summary of it.

Sample text. Security investment effectiveness is reviewed [cadence] by [role] against [measures: risk reduction observed, incidents avoided or contained, validation pass rates, audit and assessment findings closed, time-to-remediate trends]. The review states, per material investment, what was spent, what changed, and whether the investment continues. Investments that produced no measurable change are either redirected or discontinued with the reason recorded.

Replace with your practice. Name the governing body, its cadence, and the measures. KSI-PIY-RES asks for support that is reviewed and demonstrated, so name the artifact that demonstrates it.


Sample practice: cybersecurity education and training

Sample text. [Organization] runs four training tracks. All employees and contractors complete general security awareness training within [period] of hire and [cadence] thereafter. Employees in high risk roles, defined as [role list], complete role-specific training [cadence]. Development and engineering staff complete secure software delivery training [cadence], covering [topics]. Staff with incident response or disaster recovery duties complete their role training [cadence] and participate in the exercise program. Completion is tracked in [system]; overdue completions escalate to [role].

Sample text. Training effectiveness is reviewed [cadence] by [role] using [measures: assessment scores, phishing simulation click and report rates, incidents attributable to a training gap, exercise performance]. The review adjusts content and cadence where a measure moves the wrong way. Content is refreshed [cadence] and on any material change to the threat picture or the offering.

Replace with your practice. KSI-CED-RAT enumerates four minimum audiences. Cover all four explicitly, and name the effectiveness measures: completion rates alone are attendance, not effectiveness.


Sample practice: security in the software development lifecycle

Sample text. Security and privacy requirements enter [Offering]'s development lifecycle at [entry points: design review, threat model, requirement intake]. Every change passes [gates: peer review, static analysis, dependency scanning, secret scanning, infrastructure-as-code policy checks] before merge, and [gates: dynamic analysis, pre-production validation] before release. Threat models are produced for [scope] and revisited on material design change. The program is aligned to CISA Secure By Design principles, with [named practices] carrying that alignment; the alignment is reassessed [cadence].

Sample text. SDLC effectiveness is reviewed [cadence] by [role] using [measures: defects caught pre-release against defects found in production, gate bypass count and reason, mean time to remediate findings by severity, coverage of the automated gates across repositories]. Findings drive changes to the gates rather than exceptions to them.

Replace with your practice. Name the real gates and where they run. KSI-PIY-RSD asks for the effectiveness of the practice to be reviewed, so name what you measure.


Sample practice: cloud-native architecture reviews

Sample text. [Offering]'s architecture is reviewed [cadence] against six standing questions, one per indicator. Functionality and privileges for each infrastructure component and service are declared in [location] and enforced through [mechanism] (KSI-CNA-DFP). Attack surface and lateral movement exposure are assessed using [method], with segmentation enforced by [mechanism] (KSI-CNA-MAT). High availability and recovery posture is assessed per service tier against the objectives in the Recovery Planning Template (KSI-CNA-OFA). Inbound and outbound traffic restrictions are compared against the declared intent using [tooling] (KSI-CNA-RNT). Denial of service and unwanted activity protections are tested for effectiveness using [method] (KSI-CNA-RVP). Logical networking constructs enforcing traffic flow control are inventoried and reviewed (KSI-CNA-ULN). Each review records what was examined, what failed, and the corrective actions with owners and due dates.

Replace with your practice. Name the tooling and mechanism per question. Where a review is automated, say which check performs it; where it is a documented human review, say who performs it and how often.


Organization-defined values

Value Setting Notes
Security goal setting authority [executive role] KSI-PIY-RES
Governing body and meeting cadence [body; cadence] KSI-PIY-RES
Executive support artifact [minutes location] KSI-PIY-RES
Investment review cadence and measures [cadence; measures] KSI-PIY-RIS
General awareness training: onboarding window and refresh cadence [period; cadence] KSI-CED-RAT
High risk roles [role list] KSI-CED-RAT
Role-specific training cadence [cadence] KSI-CED-RAT
Secure software delivery training cadence and topics [cadence; topics] KSI-CED-RAT
Incident response and recovery role training cadence [cadence] KSI-CED-RAT
Training tracking system and escalation role [system; role] KSI-CED-RAT
Training effectiveness measures and review cadence [measures; cadence] KSI-CED-RAT
Pre-merge and pre-release security gates [gates] KSI-PIY-RSD
Threat model scope and refresh trigger [scope; trigger] KSI-PIY-RSD
CISA Secure By Design alignment practices [practices] KSI-PIY-RSD
SDLC effectiveness measures and review cadence [measures; cadence] KSI-PIY-RSD
Architecture review cadence [cadence] KSI-CNA family
Privilege and functionality declaration location [location] KSI-CNA-DFP
Segmentation and traffic control mechanisms [mechanisms] KSI-CNA-MAT, RNT, ULN
Denial of service protection and test method [protection; method] KSI-CNA-RVP
Document owner [role] Fills the authority section

Evidence

The GRC-ITSM platform does not hold your steering committee, deliver your training, or run your build pipeline. It evidences that these indicators are being met, through scheduled machine checks against the offering's architecture and validation records for the governance and training reviews. See the Continuous Monitoring and Reporting Policy and Procedures for the validation tree and the check cadences.

Practice What the platform records
Executive support and investment review (KSI-PIY-RES, RIS) Validation runs per governance review cycle, referencing the minutes
Training program (KSI-CED-RAT) The general awareness, role-based, incident response, and recovery training tasks in the recurring compliance task program, plus the security training records review, each closing as dated evidence
SDLC security (KSI-PIY-RSD) Validation runs on the effectiveness review; gate outcomes recorded as pass and fail counts
Architecture reviews (KSI-CNA family) Validation runs from scheduled machine checks on privilege definition, attack surface, availability posture, traffic restriction, and logical networking, plus documented review records where the review is human
Security improvement Improvement Projects opened from these reviews, with the cadence sweep failing a quarter with no improvement activity

Authority, review, and revision

Client fills. Name the executive who issues this document, the roles that own each of the four practices, the review cadence, and the approval path for exceptions. Record the issue date and the revision history below.

Version Date Author Change
[0.1] [date] [author] Initial draft from template