๐️ CISSP Study Note: Governance
๐️ CISSP Study Note: Governance
๐ Definition
Governance is the process by which an organization is managed and directed, encompassing how decisions are made, who makes them, and what frameworks, roles, policies, and procedures are used to guide those decisions.
It ensures that the organization’s activities align with its mission, strategy, risk appetite, and legal obligations.
๐ง Why It Matters in Cybersecurity
Governance defines the "who, what, and how" of managing security. Without it, policies become disjointed, accountability disappears, and security becomes reactive rather than strategic.
Strong governance ensures security decisions are aligned with business priorities, regulatory requirements, and ethical standards.
๐ Key Components of Governance
| Component | Description |
|---|---|
| Organizational Structure | Who is responsible for what—boards, executives, security officers, etc. |
| Policies | High-level directives that guide behavior and decisions (e.g., Acceptable Use Policy). |
| Standards and Procedures | Detailed rules and steps to carry out policies consistently. |
| Roles & Responsibilities | Clarifies accountability and authority across all levels. |
| Decision-Making Process | Defines how security-related decisions are reviewed, escalated, and approved. |
๐ Governance vs. Management
| Governance | Management |
|---|---|
| Focuses on strategy, direction, and oversight | Focuses on implementation and day-to-day operations |
| Asks “Are we doing the right things?” | Asks “Are we doing things right?” |
| Involves board/executive leadership | Involves department heads, project leads |
Governance sets the rules. Management plays the game.
✅ Example (CISSP-Style)
An organization implements a new cybersecurity governance framework, assigning roles to a Chief Information Security Officer (CISO), defining formal policy approval processes, and mandating annual policy reviews.
✅ This ensures that security decisions support business goals and regulatory obligations, and that accountability is clearly assigned.
๐ Governance Frameworks You Should Know
-
COBIT (Control Objectives for Information and Related Technology)
-
ISO/IEC 38500 (Governance of IT for the organization)
-
NIST Cybersecurity Framework (CSF) – “Identify” function
-
COSO ERM – Enterprise Risk Management
๐ Found In CISSP Domains
| Domain | Focus |
|---|---|
| ๐ Domain 1: Security and Risk Management | Governance is the foundation of all policy, risk tolerance, and security oversight. |
| ๐ Domain 7: Security Operations | Implements and enforces governance through procedures and monitoring. |
๐ Memory Hook
“Governance is the compass, not the map.”
It points the organization in the right direction—strategically, legally, and ethically.
Comments
Post a Comment