Procurement Management Plan

A part of the broader project or program management plan that sets out how the team will obtain materials and services from external suppliers beyond the performing organization.

Key Points

  • Defines the procurement strategy, including make-or-buy decisions and preferred contract types.
  • Clarifies roles, responsibilities, and approval thresholds for purchasing and contracting activities.
  • Describes how vendors will be identified, solicited, evaluated, and selected (e.g., RFP/RFQ processes and criteria).
  • Outlines timelines, coordination with schedule and budget, risk and compliance controls, and contract administration methods.

Example

A hospital expansion project plans to outsource MRI equipment and installation. The procurement management plan states the team will issue an RFP with weighted scoring (technical 60%, cost 30%, service 10%), use a fixed-price contract with milestone payments, require regulatory certifications, assign a procurement lead for vendor communications, and align delivery with the construction schedule.

PMP Example Question

Which document details how the project team will obtain products and services from external vendors, including contract type, sourcing approach, and selection criteria?

  1. Procurement management plan
  2. Scope baseline
  3. Resource management plan
  4. Make-or-buy analysis

Correct Answer: A — Procurement management plan

Explanation: The procurement management plan specifies the strategy and procedures for acquiring goods and services from outside the performing organization.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build complete project plans in minutes with AI

Stop spending hours on documentation. Learn how to use AI to create charters, WBS, schedules, risk registers, and executive reports faster—while staying fully in control. This course gives you ready-to-use prompt templates and practical workflows based on real project work. No guesswork, no fluff—just tools you can apply immediately. Backed by Udemy’s 30-day money-back guarantee, so you can start risk-free.

Learn More