For the purposes of the Compliance and Risk Process Management Pack, a program is a container for controls, risks, and policies that also serves as the security boundary for your organization's compliance and risk efforts. Programs contain controls, risks, and policies that apply to people, processes, and technology in an organization. Programs help you to determine the scope of your compliance efforts to focus on meeting a set of regulations that apply to a set of assets.
All compliance and risk efforts in the Management Pack start with creating a program, then defining a scope for the program, and finally by adding controls, risks, and policies that are designed to help meet your compliance objectives. Programs also contain configuration settings that determine how controls, risks, and policies contained in a program function.