1.3 Security Governance

CISSP Domain 1 Β· 1.3

Security Governance at a glance

Security governance is the system by which an organisation directs, oversees and controls its information security activities.

Good governance ensures that security supports the organisation's mission and business objectives rather than operating as a separate technical function.

🎯

Direction

Security priorities should support business strategy, goals and objectives.

Where are we going?
πŸ‘₯

Accountability

Roles, responsibilities and decision-making authority must be clear.

Who is responsible?
πŸ“Š

Oversight

Leadership must be able to understand security risk and monitor whether security objectives are being achieved.

Are we in control?

What is security governance?

Security governance provides the structures, responsibilities, principles and oversight mechanisms through which an organisation manages information security.

It connects cybersecurity with the wider organisation.

Instead of asking only:

Technical question

"How do we secure this system?"

governance also asks:

Business question

"What level of security does the organisation need, who is accountable for it, what risks are acceptable and how do we know our security programme is working?"

Security governance therefore operates at a higher level than individual technologies or security controls.

1 Governance vs Management A fundamental distinction

Governance sets direction

Governance is concerned with establishing direction, accountability, priorities and oversight.

It considers questions such as:

  • What security outcomes does the organisation require?
  • What risks is the organisation prepared to accept?
  • Who is accountable for security?
  • How should security support business objectives?
  • How will leadership know whether security is effective?

Management executes

Management is generally responsible for implementing the direction established through governance.

This includes activities such as:

  • implementing security programmes;
  • deploying controls;
  • managing teams;
  • operating security processes;
  • responding to incidents;
  • monitoring performance;
  • reporting results to leadership.
Governance

Sets direction, priorities, authority and accountability.

Management

Plans and executes activities needed to achieve that direction.

Example

Senior leadership decides that protecting customer information is a strategic priority and establishes requirements for strong access control across the organisation.

Security management then designs and implements an Identity and Access Management programme to achieve that objective.

Governance establishes the expectation. Management implements it.
2 Aligning security with business strategy Security exists to support the organisation

Security should support the mission

Cybersecurity should not exist as an isolated technical function.

Security activities should support the organisation's:

Mission Strategy Goals Objectives Operations Customers

The appropriate security programme therefore depends heavily on what the organisation actually does.

πŸ₯ Hospital

Patient safety and continuous access to clinical systems may make availability particularly important.

🏦 Bank

Protecting customer information, transaction integrity, fraud prevention and service availability may all be critical business requirements.

πŸ›’ Online retailer

Protecting payment information is important, but the business may also depend heavily on website availability during major sales periods.

Key principle

The purpose of cybersecurity is not to eliminate all risk. It is to enable the organisation to achieve its objectives while managing security risk appropriately.

Security should understand the business

Before recommending controls, security professionals should understand:

  • what the organisation is trying to achieve;
  • which business processes are critical;
  • which information and systems are important;
  • the organisation's legal and regulatory environment;
  • its customers and stakeholders;
  • its tolerance for disruption and risk;
  • the cost and operational impact of security controls.
Example

A security team proposes blocking all external file-sharing services.

However, the organisation's design teams collaborate constantly with external suppliers and rely on exchanging large files.

A good security solution should address the risk without unnecessarily preventing the organisation from doing business.
3 Governance structures and committees How security decisions are coordinated

Security requires organisational involvement

Cybersecurity decisions often affect multiple areas of an organisation.

Effective governance therefore usually involves more than the cybersecurity team alone.

Board / Governing Body

Provides high-level oversight and expects assurance that significant organisational risks are understood and managed.

Senior Management

Establishes organisational priorities, provides resources and ensures that security supports business objectives.

Security Leadership

Develops security strategy, advises leadership and coordinates the security programme.

Governance Committees

Bring together stakeholders from across the organisation to make coordinated decisions.

Security steering committee

An organisation may establish a security steering committee or similar governance group.

Membership might include representatives from:

Security Technology Risk Legal Compliance Privacy HR Finance Operations Business Units

The exact structure will vary between organisations.

Typical responsibilities may include:

  • reviewing significant security risks;
  • setting security priorities;
  • reviewing security performance;
  • resolving conflicts between business and security requirements;
  • supporting policy approval;
  • prioritising security investment;
  • monitoring major security initiatives.
Why involve the business?

Cybersecurity risk is ultimately business risk. Decisions about major risks should therefore involve people who understand the business consequences, not only technical security teams.

πŸ‘₯ Organisational roles and responsibilities Who does what?

Accountability must be clear

Security governance depends on people understanding their responsibilities.

If nobody knows who owns a decision, security problems can remain unresolved indefinitely.

Board / Governing Body

Provides oversight of major organisational risks and expects appropriate assurance from management.

Senior Management

Supports security strategy, establishes accountability and ensures adequate resources are available.

CISO / Security Leadership

Leads the security programme and provides professional security advice to the organisation.

Business Owners

Understand business requirements and make decisions about risks affecting their business processes.

Information / Data Owners

Determine appropriate requirements for information under their responsibility, including classification and access expectations.

Custodians

Implement and operate controls according to requirements established by owners and organisational policy.

Users

Follow organisational security requirements and use information and systems appropriately.

Internal Audit

Provides independent assessment and assurance regarding controls and governance processes.

Important CISSP concept

Security professionals advise, design and operate security controls, but business leadership and asset owners cannot simply transfer all responsibility for organisational risk to the security team.

πŸ“‹ RACI and responsibility assignment Making accountability explicit

One technique organisations can use to clarify responsibilities is a RACI model.

R β€” Responsible

The person or team performing the work.

A β€” Accountable

The person ultimately answerable for the outcome.

C β€” Consulted

People whose input is required before a decision or action.

I β€” Informed

People who need to know about the decision or outcome.

Example

A critical application needs a security risk assessment.

The security consultant may be Responsible for performing the assessment.

The application owner may remain Accountable for managing the application's risk.

Legal and privacy teams may be Consulted, while senior management may be Informed of significant findings.

Remember

Performing an activity and being ultimately accountable for its outcome are not necessarily the same thing.

🀝 Acquisitions, mergers and divestitures Security governance during organisational change

Why organisational change creates security risk

Major business changes can dramatically alter an organisation's security environment.

Examples include:

Acquisitions Mergers Divestitures Joint Ventures Restructuring Outsourcing

Acquisitions

When one organisation acquires another, it may also acquire:

  • legacy systems;
  • unknown vulnerabilities;
  • security debt;
  • third-party dependencies;
  • regulatory obligations;
  • historical incidents;
  • weak identity controls;
  • unsupported technology;
  • different security cultures.
Security due diligence

Security should be considered before and during an acquisition rather than discovering significant security problems only after systems have been integrated.

Integration risk

Connecting two organisations' networks can create new paths for attack.

Example

Company A has mature security controls and acquires Company B.

Company B operates old servers with weak patching and compromised administrator accounts.

Immediately connecting both networks could expose Company A to Company B's existing security weaknesses.

Security assessment should therefore inform integration planning.

Divestitures

A divestiture occurs when part of an organisation is sold, separated or transferred.

Security considerations may include:

  • separating networks;
  • removing access;
  • separating identities;
  • determining ownership of information;
  • transferring systems safely;
  • revoking cryptographic keys and credentials;
  • protecting information that remains confidential;
  • updating third-party agreements.
4 Security control frameworks Structured approaches to governance and security

Why use a framework?

Organisations do not need to invent an entire security programme from scratch.

Security frameworks provide structured approaches, terminology, processes and control expectations that organisations can use when designing and governing security programmes.

Different frameworks have different purposes.

🌐 ISO / IEC

The ISO/IEC 27000 family provides internationally recognised information security management standards.

ISO/IEC 27001 is particularly associated with establishing and maintaining an Information Security Management System (ISMS).

Think: structured information security management.

πŸ‡ΊπŸ‡Έ NIST

The National Institute of Standards and Technology publishes extensive cybersecurity standards, frameworks and guidance.

Examples include the NIST Cybersecurity Framework and the NIST Special Publication 800 series.

Think: broad cybersecurity guidance and structured risk management.

πŸ›οΈ COBIT

COBIT focuses strongly on governance and management of enterprise information and technology.

It helps organisations connect technology activities with business objectives, governance and accountability.

Think: enterprise IT governance.

πŸ—οΈ SABSA

Sherwood Applied Business Security Architecture is a methodology and framework for developing security architecture based on business requirements.

Think: business-driven security architecture.

πŸ’³ PCI

Payment Card Industry security standards establish security requirements for environments that handle payment-card information.

PCI DSS is one of the best-known examples.

Think: payment-card security.

☁️ FedRAMP

The Federal Risk and Authorization Management Program provides a standardised approach to security assessment and authorisation for cloud services used by US federal agencies.

Think: US federal cloud security authorisation.

CISSP perspective

You do not need to assume that one framework is universally "best". Framework selection should reflect the organisation's objectives, industry, regulatory environment and security requirements.

Framework memory aid

ISO 27001 Information Security Management System
NIST Cybersecurity frameworks and guidance
COBIT Enterprise IT governance
SABSA Business-driven security architecture
PCI DSS Payment-card security
FedRAMP US federal cloud authorisation
5 Due Care and Due Diligence A classic CISSP distinction

Why these concepts matter

Organisations and professionals are expected to act reasonably when protecting information and managing risk.

Two concepts commonly used in CISSP material are due diligence and due care.

Due Diligence

Investigating, understanding and continually evaluating risks and requirements.

Think: Know what should be done.

Due Care

Taking reasonable and appropriate action to protect the organisation and its assets.

Think: Do what should be done.

Example

Step 1 β€” Due Diligence

An organisation performs risk assessments, identifies critical vulnerabilities and evaluates the security controls required to protect customer information.

Step 2 β€” Due Care

The organisation actually implements reasonable controls, patches critical vulnerabilities and protects the information appropriately.

Easy memory aid

Due diligence = investigate.

Due care = act.

Ongoing responsibility

Security is not a one-time activity.

An organisation that implemented appropriate security controls five years ago but never reviews them may no longer be acting reasonably as threats, systems and business requirements change.

Due diligence therefore includes ongoing awareness and review.

πŸ“š How governance flows into security requirements From business direction to technical implementation

Governance establishes high-level direction, but that direction must eventually be translated into practical security requirements.

1. Business Strategy

What is the organisation trying to achieve?

2. Security Strategy

How will security support those objectives and manage important risks?

3. Policies

What high-level security requirements must the organisation follow?

4. Standards

What mandatory detailed requirements support the policies?

5. Procedures

How should specific activities be performed?

6. Controls and Operations

What technical, administrative and physical mechanisms implement the requirements?

Think top-down

Business need β†’ Security strategy β†’ Policy β†’ Standard β†’ Procedure β†’ Control.

We will examine policies, standards, procedures and guidelines in more detail in CISSP objective 1.6.

πŸ—ΊοΈ Security strategy Turning business objectives into security direction

A security strategy establishes how security will support the organisation over time.

It may consider:

Business priorities

What organisational objectives must security enable?

Risk

Which risks require the greatest attention?

Capabilities

What security capabilities are required now and in the future?

People

What skills, roles and organisational structures are needed?

Technology

Which security technologies and architectures support the strategy?

Investment

Where should limited security resources be prioritised?

Compliance

Which legal, regulatory and contractual requirements apply?

Measurement

How will the organisation know whether the strategy is succeeding?

πŸ“ˆ Governance, metrics and reporting Providing security oversight

Governance requires visibility.

Senior decision-makers need useful information about the organisation's security position.

Security reporting might include:

Major Risks Security Incidents Control Effectiveness Vulnerability Exposure Compliance Programme Progress Third-Party Risk Security Trends

Metrics should support decisions

A useful security metric should help someone understand risk, performance or required action.

Poor metric

"The vulnerability scanner found 127,438 vulnerabilities."

More useful governance information

"Twelve critical vulnerabilities remain on systems supporting the organisation's most important customer service, three of which are already being actively exploited in the wild."

Executive communication

Leadership usually needs the business meaning of a security issue, not just technical statistics.

⬇️ Top-down security governance Leadership support matters

Effective security programmes require meaningful support from senior leadership.

Without leadership support, security teams may struggle to:

  • obtain sufficient funding;
  • enforce organisational policies;
  • resolve conflicts with business teams;
  • assign clear accountability;
  • address significant risks;
  • build an organisation-wide security culture.

Bottom-up problem

A security engineer repeatedly asks teams to patch critical vulnerabilities, but business units ignore the requests because no senior leader has established responsibility or remediation expectations.

Governed approach

Leadership establishes a vulnerability management policy, assigns accountability, defines risk-based remediation requirements and provides an escalation mechanism for unresolved risk.

The second approach turns security from a personal request into an organisational requirement.

⚠️ Common mistakes Governance concepts that are easy to confuse
"Security governance is the CISO's responsibility."

Security leadership plays an important role, but organisational governance requires involvement and accountability from business and senior leadership.

"The objective of security is to eliminate risk."

Completely eliminating risk is usually impossible. Security should support business objectives while managing risk to an acceptable level.

"The strongest security control is always the best control."

A control that prevents the organisation from achieving its business objective may not be appropriate. Security decisions must consider risk and business requirements.

"Governance and management mean the same thing."

Governance establishes direction and oversight. Management implements and operates the activities required to achieve that direction.

"Due care and due diligence are identical."

For CISSP study, a useful distinction is that due diligence involves understanding and continually assessing what should be done, while due care involves taking reasonable action.

"Security owns all organisational risk."

Security teams can identify, assess and advise on risk. Business owners and organisational leadership retain responsibility for business decisions involving that risk.

CISSP Exam Perspective

Think like a business-focused security leader

Governance questions often contain technically attractive answers that are not the best governance answer.

Look for the option that considers business objectives, accountability, risk, policy and appropriate leadership involvement.

🎯 Business alignment

Mission Strategy Goals Objectives Value

πŸ‘₯ Accountability

Ownership Leadership Responsibility Authority Oversight

βš–οΈ Risk

Business Impact Risk Decisions Due Care Due Diligence Priorities
πŸ“ Practice scenarios Apply security governance principles

Scenario 1 β€” Security conflicts with business

A security team proposes disabling remote access entirely because remote access introduces additional security risk.

However, remote working is a core part of the organisation's business strategy.

Best governance approach:

Understand the business requirement and design controls that reduce remote-access risk while enabling the organisation's strategy.

Scenario 2 β€” Who accepts the risk?

A security consultant identifies a significant vulnerability in a business application.

Fixing it would require a temporary outage and the business wishes to delay remediation.

Best governance principle:

Security should clearly communicate the risk so that the appropriately authorised business owner can make an informed risk decision.

Scenario 3 β€” Acquisition

An organisation is preparing to acquire another company.

Executives want to immediately connect the acquired company's network to the corporate environment.

Best security approach:

Perform appropriate security due diligence and assess the acquired environment before integration.

Scenario 4 β€” Security framework

An organisation needs a structured security programme.

A security professional recommends adopting a framework simply because another company uses it.

What is missing?

Framework selection should consider the organisation's own business, regulatory, risk and security requirements.

Scenario 5 β€” Due diligence without due care

A risk assessment identifies a critical vulnerability on an internet-facing system.

Management acknowledges the report but takes no action for several years.

What is the concern?

Identifying the problem demonstrates investigation, but reasonable protective action is also required.

Scenario 6 β€” Executive reporting

The CISO presents the board with twenty pages of CVE identifiers, firewall logs and vulnerability scanner statistics.

What would improve governance?

Translate technical findings into understandable business risks, trends, decisions and required actions.

Security governance flow

A useful way to visualise governance is as a chain from business direction to security outcomes.

🎯 Business Strategy β†’ What must the organisation achieve?
πŸ›‘οΈ Security Strategy β†’ How will security support it?
πŸ“œ Policies & Frameworks β†’ What requirements apply?
βš™οΈ Management & Controls β†’ How will requirements be implemented?
πŸ“Š Monitoring & Assurance β†’ Is it actually working?

Quick memory aid

Governance Sets DIRECTION
Management EXECUTES the direction
Business Alignment Security ENABLES the organisation
Accountability Know WHO owns the decision
Due Diligence KNOW what should be done
Due Care DO what should be done

Direct. Align. Assign. Oversee.

Key takeaways

Security governance connects cybersecurity with the organisation's mission and business objectives.

Governance sets direction and provides oversight; management executes that direction.

Security should enable the organisation to achieve its goals while managing security risk appropriately.

Roles and accountability must be clear. Security teams may advise and operate controls, but organisational risk ultimately requires business ownership and leadership involvement.

Governance structures such as security committees help coordinate security decisions across technology, risk, legal, compliance and the business.

Acquisitions, mergers and divestitures can introduce significant security risk and should include appropriate security assessment and due diligence.

Frameworks such as ISO, NIST, COBIT, SABSA, PCI and FedRAMP provide structured approaches for different security and governance needs.

For CISSP study: remember due diligence as understanding what should be done and due care as taking reasonable action.

Most importantly, good governance ensures that cybersecurity is not simply a technical activity β€” it is part of how the organisation makes decisions, manages risk and achieves its objectives.