"Select and support a 'Security Program Manager.' This person doesn’t need to be a security expert or even an IT professional. The Security Program Manager ensures your organization implements all the key elements of a strong cybersecurity program."
Somewhat contradictory. A "security program manager" can't implement good security if they don't know what it looks like, even if given a checklist.
This reads like the sort of document that the government publishes because it has a fiduciary to protect the vaunted "small business owner," similar to "fraud awareness" campaigns, but is more laying the groundwork to say that they told you so, rather than real protection.