1.3 Security Governance
Security Governance at a glance
Security governance is the system by which an organisation directs, oversees and controls its information security activities.
Good governance ensures that security supports the organisation's mission and business objectives rather than operating as a separate technical function.
Direction
Security priorities should support business strategy, goals and objectives.
Where are we going?Accountability
Roles, responsibilities and decision-making authority must be clear.
Who is responsible?Oversight
Leadership must be able to understand security risk and monitor whether security objectives are being achieved.
Are we in control?What is security governance?
Security governance provides the structures, responsibilities, principles and oversight mechanisms through which an organisation manages information security.
It connects cybersecurity with the wider organisation.
Instead of asking only:
"How do we secure this system?"
governance also asks:
"What level of security does the organisation need, who is accountable for it, what risks are acceptable and how do we know our security programme is working?"
Security governance therefore operates at a higher level than individual technologies or security controls.
1 Governance vs Management A fundamental distinction
Governance sets direction
Governance is concerned with establishing direction, accountability, priorities and oversight.
It considers questions such as:
- What security outcomes does the organisation require?
- What risks is the organisation prepared to accept?
- Who is accountable for security?
- How should security support business objectives?
- How will leadership know whether security is effective?
Management executes
Management is generally responsible for implementing the direction established through governance.
This includes activities such as:
- implementing security programmes;
- deploying controls;
- managing teams;
- operating security processes;
- responding to incidents;
- monitoring performance;
- reporting results to leadership.
Sets direction, priorities, authority and accountability.
Plans and executes activities needed to achieve that direction.
Senior leadership decides that protecting customer information is a strategic priority and establishes requirements for strong access control across the organisation.
Security management then designs and implements an Identity and Access Management programme to achieve that objective.
Governance establishes the expectation. Management implements it.2 Aligning security with business strategy Security exists to support the organisation
Security should support the mission
Cybersecurity should not exist as an isolated technical function.
Security activities should support the organisation's:
The appropriate security programme therefore depends heavily on what the organisation actually does.
π₯ Hospital
Patient safety and continuous access to clinical systems may make availability particularly important.
π¦ Bank
Protecting customer information, transaction integrity, fraud prevention and service availability may all be critical business requirements.
π Online retailer
Protecting payment information is important, but the business may also depend heavily on website availability during major sales periods.
The purpose of cybersecurity is not to eliminate all risk. It is to enable the organisation to achieve its objectives while managing security risk appropriately.
Security should understand the business
Before recommending controls, security professionals should understand:
- what the organisation is trying to achieve;
- which business processes are critical;
- which information and systems are important;
- the organisation's legal and regulatory environment;
- its customers and stakeholders;
- its tolerance for disruption and risk;
- the cost and operational impact of security controls.
A security team proposes blocking all external file-sharing services.
However, the organisation's design teams collaborate constantly with external suppliers and rely on exchanging large files.
A good security solution should address the risk without unnecessarily preventing the organisation from doing business.3 Governance structures and committees How security decisions are coordinated
Security requires organisational involvement
Cybersecurity decisions often affect multiple areas of an organisation.
Effective governance therefore usually involves more than the cybersecurity team alone.
Provides high-level oversight and expects assurance that significant organisational risks are understood and managed.
Establishes organisational priorities, provides resources and ensures that security supports business objectives.
Develops security strategy, advises leadership and coordinates the security programme.
Bring together stakeholders from across the organisation to make coordinated decisions.
Security steering committee
An organisation may establish a security steering committee or similar governance group.
Membership might include representatives from:
The exact structure will vary between organisations.
Typical responsibilities may include:
- reviewing significant security risks;
- setting security priorities;
- reviewing security performance;
- resolving conflicts between business and security requirements;
- supporting policy approval;
- prioritising security investment;
- monitoring major security initiatives.
Cybersecurity risk is ultimately business risk. Decisions about major risks should therefore involve people who understand the business consequences, not only technical security teams.
π₯ Organisational roles and responsibilities Who does what?
Accountability must be clear
Security governance depends on people understanding their responsibilities.
If nobody knows who owns a decision, security problems can remain unresolved indefinitely.
Provides oversight of major organisational risks and expects appropriate assurance from management.
Supports security strategy, establishes accountability and ensures adequate resources are available.
Leads the security programme and provides professional security advice to the organisation.
Understand business requirements and make decisions about risks affecting their business processes.
Determine appropriate requirements for information under their responsibility, including classification and access expectations.
Implement and operate controls according to requirements established by owners and organisational policy.
Follow organisational security requirements and use information and systems appropriately.
Provides independent assessment and assurance regarding controls and governance processes.
Security professionals advise, design and operate security controls, but business leadership and asset owners cannot simply transfer all responsibility for organisational risk to the security team.
π RACI and responsibility assignment Making accountability explicit
One technique organisations can use to clarify responsibilities is a RACI model.
The person or team performing the work.
The person ultimately answerable for the outcome.
People whose input is required before a decision or action.
People who need to know about the decision or outcome.
A critical application needs a security risk assessment.
The security consultant may be Responsible for performing the assessment.
The application owner may remain Accountable for managing the application's risk.
Legal and privacy teams may be Consulted, while senior management may be Informed of significant findings.
Performing an activity and being ultimately accountable for its outcome are not necessarily the same thing.
π€ Acquisitions, mergers and divestitures Security governance during organisational change
Why organisational change creates security risk
Major business changes can dramatically alter an organisation's security environment.
Examples include:
Acquisitions
When one organisation acquires another, it may also acquire:
- legacy systems;
- unknown vulnerabilities;
- security debt;
- third-party dependencies;
- regulatory obligations;
- historical incidents;
- weak identity controls;
- unsupported technology;
- different security cultures.
Security should be considered before and during an acquisition rather than discovering significant security problems only after systems have been integrated.
Integration risk
Connecting two organisations' networks can create new paths for attack.
Company A has mature security controls and acquires Company B.
Company B operates old servers with weak patching and compromised administrator accounts.
Immediately connecting both networks could expose Company A to Company B's existing security weaknesses.
Security assessment should therefore inform integration planning.Divestitures
A divestiture occurs when part of an organisation is sold, separated or transferred.
Security considerations may include:
- separating networks;
- removing access;
- separating identities;
- determining ownership of information;
- transferring systems safely;
- revoking cryptographic keys and credentials;
- protecting information that remains confidential;
- updating third-party agreements.
4 Security control frameworks Structured approaches to governance and security
Why use a framework?
Organisations do not need to invent an entire security programme from scratch.
Security frameworks provide structured approaches, terminology, processes and control expectations that organisations can use when designing and governing security programmes.
Different frameworks have different purposes.
π ISO / IEC
The ISO/IEC 27000 family provides internationally recognised information security management standards.
ISO/IEC 27001 is particularly associated with establishing and maintaining an Information Security Management System (ISMS).
Think: structured information security management.
πΊπΈ NIST
The National Institute of Standards and Technology publishes extensive cybersecurity standards, frameworks and guidance.
Examples include the NIST Cybersecurity Framework and the NIST Special Publication 800 series.
Think: broad cybersecurity guidance and structured risk management.
ποΈ COBIT
COBIT focuses strongly on governance and management of enterprise information and technology.
It helps organisations connect technology activities with business objectives, governance and accountability.
Think: enterprise IT governance.
ποΈ SABSA
Sherwood Applied Business Security Architecture is a methodology and framework for developing security architecture based on business requirements.
Think: business-driven security architecture.
π³ PCI
Payment Card Industry security standards establish security requirements for environments that handle payment-card information.
PCI DSS is one of the best-known examples.
Think: payment-card security.
βοΈ FedRAMP
The Federal Risk and Authorization Management Program provides a standardised approach to security assessment and authorisation for cloud services used by US federal agencies.
Think: US federal cloud security authorisation.
You do not need to assume that one framework is universally "best". Framework selection should reflect the organisation's objectives, industry, regulatory environment and security requirements.
Framework memory aid
5 Due Care and Due Diligence A classic CISSP distinction
Why these concepts matter
Organisations and professionals are expected to act reasonably when protecting information and managing risk.
Two concepts commonly used in CISSP material are due diligence and due care.
Investigating, understanding and continually evaluating risks and requirements.
Think: Know what should be done.
Taking reasonable and appropriate action to protect the organisation and its assets.
Think: Do what should be done.
Example
An organisation performs risk assessments, identifies critical vulnerabilities and evaluates the security controls required to protect customer information.
The organisation actually implements reasonable controls, patches critical vulnerabilities and protects the information appropriately.
Due diligence = investigate.
Due care = act.
Ongoing responsibility
Security is not a one-time activity.
An organisation that implemented appropriate security controls five years ago but never reviews them may no longer be acting reasonably as threats, systems and business requirements change.
Due diligence therefore includes ongoing awareness and review.
π How governance flows into security requirements From business direction to technical implementation
Governance establishes high-level direction, but that direction must eventually be translated into practical security requirements.
What is the organisation trying to achieve?
How will security support those objectives and manage important risks?
What high-level security requirements must the organisation follow?
What mandatory detailed requirements support the policies?
How should specific activities be performed?
What technical, administrative and physical mechanisms implement the requirements?
Business need β Security strategy β Policy β Standard β Procedure β Control.
We will examine policies, standards, procedures and guidelines in more detail in CISSP objective 1.6.
πΊοΈ Security strategy Turning business objectives into security direction
A security strategy establishes how security will support the organisation over time.
It may consider:
What organisational objectives must security enable?
Which risks require the greatest attention?
What security capabilities are required now and in the future?
What skills, roles and organisational structures are needed?
Which security technologies and architectures support the strategy?
Where should limited security resources be prioritised?
Which legal, regulatory and contractual requirements apply?
How will the organisation know whether the strategy is succeeding?
π Governance, metrics and reporting Providing security oversight
Governance requires visibility.
Senior decision-makers need useful information about the organisation's security position.
Security reporting might include:
Metrics should support decisions
A useful security metric should help someone understand risk, performance or required action.
"The vulnerability scanner found 127,438 vulnerabilities."
"Twelve critical vulnerabilities remain on systems supporting the organisation's most important customer service, three of which are already being actively exploited in the wild."
Leadership usually needs the business meaning of a security issue, not just technical statistics.
β¬οΈ Top-down security governance Leadership support matters
Effective security programmes require meaningful support from senior leadership.
Without leadership support, security teams may struggle to:
- obtain sufficient funding;
- enforce organisational policies;
- resolve conflicts with business teams;
- assign clear accountability;
- address significant risks;
- build an organisation-wide security culture.
Bottom-up problem
A security engineer repeatedly asks teams to patch critical vulnerabilities, but business units ignore the requests because no senior leader has established responsibility or remediation expectations.
Governed approach
Leadership establishes a vulnerability management policy, assigns accountability, defines risk-based remediation requirements and provides an escalation mechanism for unresolved risk.
The second approach turns security from a personal request into an organisational requirement.
β οΈ Common mistakes Governance concepts that are easy to confuse
Security leadership plays an important role, but organisational governance requires involvement and accountability from business and senior leadership.
Completely eliminating risk is usually impossible. Security should support business objectives while managing risk to an acceptable level.
A control that prevents the organisation from achieving its business objective may not be appropriate. Security decisions must consider risk and business requirements.
Governance establishes direction and oversight. Management implements and operates the activities required to achieve that direction.
For CISSP study, a useful distinction is that due diligence involves understanding and continually assessing what should be done, while due care involves taking reasonable action.
Security teams can identify, assess and advise on risk. Business owners and organisational leadership retain responsibility for business decisions involving that risk.
Think like a business-focused security leader
Governance questions often contain technically attractive answers that are not the best governance answer.
Look for the option that considers business objectives, accountability, risk, policy and appropriate leadership involvement.
π― Business alignment
π₯ Accountability
βοΈ Risk
π Practice scenarios Apply security governance principles
Scenario 1 β Security conflicts with business
A security team proposes disabling remote access entirely because remote access introduces additional security risk.
However, remote working is a core part of the organisation's business strategy.
Best governance approach:
Understand the business requirement and design controls that reduce remote-access risk while enabling the organisation's strategy.
Scenario 2 β Who accepts the risk?
A security consultant identifies a significant vulnerability in a business application.
Fixing it would require a temporary outage and the business wishes to delay remediation.
Best governance principle:
Security should clearly communicate the risk so that the appropriately authorised business owner can make an informed risk decision.
Scenario 3 β Acquisition
An organisation is preparing to acquire another company.
Executives want to immediately connect the acquired company's network to the corporate environment.
Best security approach:
Perform appropriate security due diligence and assess the acquired environment before integration.
Scenario 4 β Security framework
An organisation needs a structured security programme.
A security professional recommends adopting a framework simply because another company uses it.
What is missing?
Framework selection should consider the organisation's own business, regulatory, risk and security requirements.
Scenario 5 β Due diligence without due care
A risk assessment identifies a critical vulnerability on an internet-facing system.
Management acknowledges the report but takes no action for several years.
What is the concern?
Identifying the problem demonstrates investigation, but reasonable protective action is also required.
Scenario 6 β Executive reporting
The CISO presents the board with twenty pages of CVE identifiers, firewall logs and vulnerability scanner statistics.
What would improve governance?
Translate technical findings into understandable business risks, trends, decisions and required actions.
Security governance flow
A useful way to visualise governance is as a chain from business direction to security outcomes.
Quick memory aid
Direct. Align. Assign. Oversee.
Key takeaways
Security governance connects cybersecurity with the organisation's mission and business objectives.
Governance sets direction and provides oversight; management executes that direction.
Security should enable the organisation to achieve its goals while managing security risk appropriately.
Roles and accountability must be clear. Security teams may advise and operate controls, but organisational risk ultimately requires business ownership and leadership involvement.
Governance structures such as security committees help coordinate security decisions across technology, risk, legal, compliance and the business.
Acquisitions, mergers and divestitures can introduce significant security risk and should include appropriate security assessment and due diligence.
Frameworks such as ISO, NIST, COBIT, SABSA, PCI and FedRAMP provide structured approaches for different security and governance needs.
For CISSP study: remember due diligence as understanding what should be done and due care as taking reasonable action.
Most importantly, good governance ensures that cybersecurity is not simply a technical activity β it is part of how the organisation makes decisions, manages risk and achieves its objectives.
