Security Governance
What is Security Governance?
The set of responsibilities and practices exercised by the board and executive management to provide strategic direction and oversight for information security.
Terms that appear alongside security governance
Each of these is named in at least one of the same controls as security governance. The number is how many controls name both.
- governance 58 shared controls
- information security 46 shared controls
- policy 12 shared controls
- roles and responsibilities 8 shared controls
- risk appetite 7 shared controls
- policy framework 7 shared controls
- security policy framework 7 shared controls
- security program management 6 shared controls
Frameworks that govern security governance
What the standards actually require on security governance
Requirements naming security governance across 6 standards, quoted from the control text.
Entities must take a risk-based approach to protective security, with clear governance, accountability, and performance reporting that drives continuous improvement across security functions.
PSPF-2024-OUTCOME-1 · Security Governance Outcome →Establishment of leadership, institutions and responsibilities to coordinate cyber security.
MALABO-Art26 · Cyber Security Governance and Leadership →Establish a formal governance framework for CDR data information security risk, document practices and responsibilities including those of senior management, maintain an information security policy, and review the framework at least annually.
AUCDR-IS-STEP1 · Step 1 - Define and implement security governance for CDR data →Provide governance and strategic direction for cyber security, with board/executive oversight.
AESCSF-CPM-2 · Cyber security governance and strategy →Defence and its partners must establish security governance (accountable authority, roles and responsibilities), manage security risk, foster a positive security culture, and provide assurance over the security of people, information and assets.
DSPF-GOV-PRIN · Security governance, risk management and culture →Security governance structure. Control from IEC 62443 framework, domain: IEC 62443: Asset Identification & Governance.
IEC62443-03 · Security governance structure →Questions people ask about security governance
What is Security Governance?
Why is Security Governance important for compliance?
Which compliance frameworks address Security Governance?
Where can I learn more about Security Governance?
See how Security Governance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.