Security Governance
Security governance is the system an organization uses to direct and oversee cybersecurity risk. It connects business objectives, risk appetite, policies, assigned decision rights, controls, assurance, and reporting so leaders can decide what protection is required and verify that it works.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Security Governance
Security governance is the system used to direct and oversee cybersecurity risk. It connects organizational objectives to risk decisions, policies, accountable roles, controls, assurance, and reporting. Governance determines who may make a decision, which evidence supports it, and how leaders learn whether the decision still protects the organization.
Governance is not the same as security operations. Operations configure safeguards, monitor systems, and respond to incidents. Governance sets direction and constraints for that work. It also receives evidence from operations and decides whether the remaining risk is acceptable. The two depend on each other. Governance without operational evidence becomes paperwork. Operations without governance can optimize technical activity while missing business priorities.
The governance system
A working governance system has six connected parts:
- Organizational context identifies mission, stakeholders, legal duties, contractual duties, critical services, and dependencies.
- Risk direction states risk appetite, risk tolerance, priorities, and escalation thresholds.
- Accountability assigns decision rights to a governing body, executives, risk owners, control owners, and assurance functions.
- Policy and control structure translates direction into mandatory rules, expected outcomes, and safeguards.
- Assurance and measurement tests whether controls are designed appropriately, operating as intended, and producing the expected risk reduction.
- Oversight and improvement reviews performance, exceptions, incidents, audit results, and environmental changes, then adjusts direction.
NIST Cybersecurity Framework 2.0 places these concerns in the Govern function. Its categories cover organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management. Govern surrounds the other CSF functions because direction and oversight affect identification, protection, detection, response, and recovery.
How a risk decision flows
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
Supports
- CSF Core, Profiles, and Tiers
- Govern function definition and categories
- High-level outcome model and non-prescriptive use
- Timeline event for CSF 2.0
- https://www.nist.gov/cyberframework/faqs
Supports
- Reason Govern became a separate function
- Alignment of governance, enterprise risk, and legal obligations
- https://csrc.nist.gov/pubs/sp/1303/final
Supports
- Integration of cybersecurity risk with enterprise risk management
- Risk monitoring, evaluation, adjustment, and common language
- Appetite, tolerance, and organizational risk communication
- https://csrc.nist.gov/pubs/ir/8286/r1/final
Supports
- Cybersecurity risk registers
- Risk aggregation into enterprise risk portfolios
- Linking cyber risk to strategic objectives and fiduciary responsibilities
- https://csrc.nist.gov/News/2020/integrating-cybersecurity-and-enterprise-risk-mgmt
Supports
- 2020 publication date and purpose of NIST IR 8286
- Timeline event connecting cybersecurity and enterprise risk management
- https://csrc.nist.gov/pubs/sp/800/100/upd1/final
Supports
- Information security program governance and management roles
- Security program elements, controls, and performance measures
- 2006 publication and 2007 final update timeline events
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-100.pdf
Supports
- Information security governance requirements
- Governance, management, and operational distinctions
- Policy, authority, and program oversight
- https://www.iso.org/standard/27001
Supports
- ISMS definition and requirements-based approach
- Risk management and continual improvement
- 2022 third-edition timeline event
- https://www.iso.org/contents/data/standard/05/45/54534.html
Supports
- 2005 first-edition lifecycle record
- 2013 second-edition publication and requirements
- ISMS risk assessment and treatment
- https://www.cisecurity.org/controls/v8
Supports
- Prioritized and measurable safeguards
- Alignment with governance, regulatory, and process frameworks
- Control implementation focus
- https://cas.docs.cisecurity.org/en/latest/source/About%20the%20CIS%20Controls/
Supports
- Measuring whether safeguards are implemented and working
- Distinction between control selection and assessment
- https://www.cisecurity.org/controls/cis-controls-navigator/v8
Supports
- Mappings between CIS safeguards and other standards
- Reuse of control evidence across external requirements
- https://www.cisecurity.org/about-us/media/press-release/center-for-internet-security-releases-cis-controls-v8-1-with-new-governance-recommendations
Supports
- 2024 CIS Controls 8.1 governance recommendations
- Governance policies, procedures, processes, and compliance evidence
- https://www.isaca.org/store2/product/CB19FGM
Supports
- COBIT scope across enterprise information and technology
- Governance and management objectives
- Forty-objective Core Model
- https://www.cisa.gov/cybersecurity-performance-goals
Supports
- Prioritized and measurable cybersecurity outcomes
- Alignment of CISA goals with CSF functions
- Use of baselines to support risk reduction
- https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity
Supports
- 2013 direction to develop a voluntary risk-based cybersecurity framework
- Timeline origin of the NIST CSF
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- 2014 CSF 1.0 release date
- Core, Tiers, Profiles, and five original Functions
- https://www.nist.gov/publications/framework-improving-critical-infrastructure-cybersecurity-version-11
Supports
- 2018 CSF 1.1 release date
- Self-assessment and supply chain risk management updates
- https://www.sec.gov/rules-regulations/2023/07/s7-09-22
Supports
- Cybersecurity risk, strategy, governance, and incident disclosure requirements
- Board oversight and management role disclosures
- 2023 final-rule timeline event
- https://github.com/sindresorhus/awesome
Supports
- Discovery route to the curated Awesome Security list
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Wazuh as security monitoring and compliance tooling
- Discovery of Rudder as configuration management and compliance tooling
- https://documentation.wazuh.com/current/compliance/index.html
Supports
- Wazuh regulatory compliance monitoring capabilities
- Log analysis, policy violation detection, and framework dashboards
- Awesome Links rationale
- https://docs.rudder.io/reference/9.1/usage/configuration_management.html
Supports
- Rudder audit and enforce modes
- Configuration drift assessment and compliance reporting
- Awesome Links rationale
- https://www.servicenow.com/products/governance-risk-and-compliance.html
Supports
- ServiceNow Integrated Risk Management landscape placement
- Enterprise risk workflow and governance records
- https://www.archerirm.com/
Supports
- Archer Evolv landscape placement
- Traceability from regulatory source to obligations, controls, and evidence
- https://www.metricstream.com/products/it-and-cyber-risk-management.htm
Supports
- MetricStream CyberGRC landscape placement
- IT asset, threat, control, assessment, and risk aggregation
- https://www.onetrust.com/solutions/tech-risk-and-compliance/
Supports
- OneTrust Tech Risk and Compliance landscape placement
- Framework mapping, control libraries, evidence, and risk views
- https://www.logicgate.com/
Supports
- LogicGate Risk Cloud landscape placement
- Configurable cyber risk and compliance workflows
- https://optro.ai/platform
Supports
- Optro landscape placement
- Connected risk, control, audit, and IT compliance reporting
- https://hyperproof.io/product/
Supports
- Hyperproof landscape placement
- Compliance, risk register, control health, and evidence workflows
- https://www.vanta.com/vanta-platform
Supports
- Vanta landscape placement
- Automated evidence and continuous control monitoring
- https://drata.com/products/compliance
Supports
- Drata landscape placement
- Evidence, audit collaboration, approvals, and remediation workflows
- https://secureframe.com/compliance-platform
Supports
- Secureframe landscape placement
- Control monitoring, evidence, vendor, and audit workflows
