Skip to content

Security Governance

What is Security Governance?

The set of responsibilities and practices exercised by the board and executive management to provide strategic direction and oversight for information security.

Governance

Each of these is named in at least one of the same controls as security governance. The number is how many controls name both.

What the standards actually require on security governance

Requirements naming security governance across 6 standards, quoted from the control text.

Entities must take a risk-based approach to protective security, with clear governance, accountability, and performance reporting that drives continuous improvement across security functions.

PSPF-2024-OUTCOME-1 · Security Governance Outcome

Establishment of leadership, institutions and responsibilities to coordinate cyber security.

MALABO-Art26 · Cyber Security Governance and Leadership

Establish a formal governance framework for CDR data information security risk, document practices and responsibilities including those of senior management, maintain an information security policy, and review the framework at least annually.

AUCDR-IS-STEP1 · Step 1 - Define and implement security governance for CDR data

Provide governance and strategic direction for cyber security, with board/executive oversight.

AESCSF-CPM-2 · Cyber security governance and strategy

Defence and its partners must establish security governance (accountable authority, roles and responsibilities), manage security risk, foster a positive security culture, and provide assurance over the security of people, information and assets.

DSPF-GOV-PRIN · Security governance, risk management and culture
IEC 624431 control

Security governance structure. Control from IEC 62443 framework, domain: IEC 62443: Asset Identification & Governance.

IEC62443-03 · Security governance structure

Questions people ask about security governance

What is Security Governance?
The set of responsibilities and practices exercised by the board and executive management to provide strategic direction and oversight for information security.
Why is Security Governance important for compliance?
Security Governance is a key concept in Governance. Understanding security governance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Governance?
Security Governance appears in the requirement text of Protective Security Policy Framework (PSPF) Release 2024, African Union Malabo Convention, Australia Consumer Data Right - Banking (CDR), Australian Energy Sector Cyber Security Framework (AESCSF), Defence Security Principles Framework (DSPF). Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Governance?
Explore our compliance framework pages to see how security governance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Governance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.