๐Ÿ›️ CISSP Study Note: Governance

๐Ÿ›️ CISSP Study Note: Governance


๐Ÿ” Definition

Governance is the process by which an organization is managed and directed, encompassing how decisions are made, who makes them, and what frameworks, roles, policies, and procedures are used to guide those decisions.

It ensures that the organization’s activities align with its mission, strategy, risk appetite, and legal obligations.


๐Ÿง  Why It Matters in Cybersecurity

Governance defines the "who, what, and how" of managing security. Without it, policies become disjointed, accountability disappears, and security becomes reactive rather than strategic.
Strong governance ensures security decisions are aligned with business priorities, regulatory requirements, and ethical standards.


๐Ÿ“‹ Key Components of Governance

Component Description
Organizational Structure Who is responsible for what—boards, executives, security officers, etc.
Policies High-level directives that guide behavior and decisions (e.g., Acceptable Use Policy).
Standards and Procedures Detailed rules and steps to carry out policies consistently.
Roles & Responsibilities Clarifies accountability and authority across all levels.
Decision-Making Process Defines how security-related decisions are reviewed, escalated, and approved.

๐Ÿ” Governance vs. Management

Governance Management
Focuses on strategy, direction, and oversight Focuses on implementation and day-to-day operations
Asks “Are we doing the right things?” Asks “Are we doing things right?”
Involves board/executive leadership Involves department heads, project leads

Governance sets the rules. Management plays the game.


✅ Example (CISSP-Style)

An organization implements a new cybersecurity governance framework, assigning roles to a Chief Information Security Officer (CISO), defining formal policy approval processes, and mandating annual policy reviews.
✅ This ensures that security decisions support business goals and regulatory obligations, and that accountability is clearly assigned.


๐Ÿ“Œ Governance Frameworks You Should Know

  • COBIT (Control Objectives for Information and Related Technology)

  • ISO/IEC 38500 (Governance of IT for the organization)

  • NIST Cybersecurity Framework (CSF) – “Identify” function

  • COSO ERM – Enterprise Risk Management


๐Ÿ“– Found In CISSP Domains

Domain Focus
๐Ÿ“˜ Domain 1: Security and Risk Management Governance is the foundation of all policy, risk tolerance, and security oversight.
๐Ÿ“˜ Domain 7: Security Operations Implements and enforces governance through procedures and monitoring.

๐Ÿ”‘ Memory Hook

“Governance is the compass, not the map.”
It points the organization in the right direction—strategically, legally, and ethically.


Comments

Popular posts from this blog

๐Ÿงญ CISSP Study Note: Guidelines

๐Ÿ’ธ CISSP Study Note: Risk Transference

๐Ÿ“ CISSP Study Note: Standards