1.2. Evaluate and apply security governance principles

1.2. Evaluate and apply security governance principles.

Security governance is the collection of practices related to supporting, defining, and directing the security efforts of an organization. 

The common goal of governance is to maintain business processes while striving towards growth and resiliency.

Few aspects of governance are imposed on organizations due to legislative and regulatory compliance needs, whereas others are imposed by industry guidelines or license requirements. 

All forms of governance, including security governance, must be assessed and verified from time to time. 

Various requirements for auditing and validation my be present due to government regulation or industry best practices and is vary from industry to industry and from country to country. 

The governance become more complex when many organizations expand and adapt to deal with global market as the laws in different countries differ or in fact conflict. 

The management  should address threats and risk with a focus on eliminating downtime and keeping potential loss or damage to a minimum.

Security governance is the implementation of a security solution and a management method that are tightly interconnected. 

Security is a business operations issue, commonly managed by a governance committee or at least a board of directors under the group of experts whose primary task is to oversee and guide the actions of security and operations for an organization.

There are numerous security frameworks and governance guidelines (viz NIST 800-53 or 800-100), NIST guidance is focused on government and military use, it can be adopted and adapted by other types of organization as well.

Post a Comment

0 Comments