secplus

Dashboard / 5.0 Security Program Management and Oversight

5.1 Summarize elements of effective security governance

Official exam objective outline (8 topics)
  • Guidelines
  • Policies
    • Acceptable use policy (AUP)
    • Information security policies
    • Business continuity
    • Disaster recovery
    • Incident response
    • Software development lifecycle (SDLC)
    • Change management
  • Standards
    • Password
    • Access control
    • Physical security
    • Encryption
  • Procedures
    • Change management
    • Onboarding/offboarding
    • Playbooks
  • External considerations
    • Regulatory
    • Legal
    • Industry
    • Local/regional
    • National
    • Global
  • Monitoring and revision
  • Types of governance structures
    • Boards
    • Committees
    • Government entities
    • Centralized/decentralized
  • Roles and responsibilities for systems and data
    • Owners
    • Controllers
    • Processors
    • Custodians/stewards

★ Starred in your notes: regulatory compliance (SOX, HIPAA, GLBA, GDPR, PCI DSS) · key escrow (external) vs. recovery agent (internal).

Breakdown 1 — The document hierarchy

DocumentWhat it isBinding?Example
PolicyHigh-level what and why, approved by managementMandatory"All remote access requires MFA"
StandardSpecific requirements that implement a policyMandatory"Passwords ≥ 14 chars; AES-256 for data at rest"
ProcedureStep-by-step howMandatory"How to onboard a new hire"
GuidelineRecommended practicesOptional"Tips for choosing a passphrase"
PlaybookProcedure for a specific scenario (incident type)"Ransomware playbook"

From class — security documentation: framework (NIST CSF, ISO 27001, CIS) → policy. Typical policies: AUP (acceptable use policy), BCP (business continuity policy/plan), change management policy; credential/password policies (key escrow → external holds the private key; recovery agent → internal); asset management; secure personnel policy: clean desk (keep information away from others' eyes), separation of duties (no single person controls a whole process — SOX compliance).

Policies the exam lists: AUP · Information security policies · Business continuity · Disaster recovery · Incident response · SDLC (secure development lifecycle) · Change management. Standards: password · access control · physical security · encryption. Procedures: change management · onboarding/offboarding · playbooks.

Breakdown 2 — External considerations

DriverExamples
RegulatoryHIPAA (health), SOX (public-company financial reporting), GLBA (financial privacy), PCI DSS (card data — contractual, not law), GDPR (EU personal data), FERPA (student records)
LegalContracts, breach-notification laws, e-discovery
IndustryPCI DSS, NERC CIP (utilities), sector ISAC guidance
Local/regional · National · GlobalState privacy laws (CCPA) · federal (HIPAA) · GDPR — the strictest applicable one usually wins

From class: SOX → accurate financial reporting; GLBA → finance; GDPR → EU person protected wherever the data goes (keywords: data sovereignty, right to be forgotten, data controller, data processor); PCI DSS → credit cards ("don't worry about the full compliance list"); HIPAA → health. Due diligence → do your part before (investigate/verify); due care → act responsibly on an ongoing basis.

Breakdown 3 — Monitoring, revision, and governance structures

  • Monitoring and revision: policies are reviewed on a schedule and after incidents, audits, new laws, or major changes; version-controlled with owners.
  • Governance structures: Boards (directors — ultimate accountability), committees (steering/security committees that set direction), government entities (regulators), centralized (one security org sets rules) vs. decentralized (business units own their security within a framework).

Breakdown 4 — Roles and responsibilities for systems and data

RoleResponsibilityGDPR-speak
OwnerAccountable for the asset/data: classification, access approval, risk acceptance (usually a business executive)
ControllerDecides why and how personal data is processedThe company collecting customer data
ProcessorProcesses data on behalf of the controllerThe cloud/payroll vendor
Custodian / stewardDay-to-day handling: backups, permissions, integrity (IT/DBA)

Exam tip: "Who classifies the data?" → owner. "Who implements backups per the owner's rules?" → custodian. "SaaS vendor processing your customer records" → processor; you are the controller. "Mandatory document with specific settings" → standard; "recommended" → guideline; "step-by-step" → procedure.

Quick self-check

  • Policy vs. standard vs. procedure vs. guideline?
  • Controller vs. processor?
  • Which law covers public-company financial reporting? (SOX.)

Sources: 20260917_173216.jpg, 20260917_173221.jpg, 20260917_173259.jpg, 20260917_173307.jpg