MODULE 10 โ Introduction to Security Governance
Learning Objectives
Learners will:
- Understand the role of policies, standards, and procedures.
- Explain compliance frameworks (ISO 27001, NIST).
- Evaluate governance structures for organisations.
- Apply governance principles to risk management.
Module Overview
Governance ensures cybersecurity is not merely technical but organisational. This module introduces frameworks that guide decision-making, accountability, and compliance.
1. Governance Components
- Policies โ leadership intent
- Standards โ mandatory requirements
- Procedures โ operational steps
- Guidelines โ optional best practices
2. Frameworks
2.1 ISO 27001
International standard for information security management.
2.2 NIST CSF
Framework built around identifyโprotectโdetectโrespondโrecover.
2.3 COBIT
Governance for enterprise IT.
3. Security Roles
- CISO
- Security engineers
- Governance & risk managers
- Internal auditors
4. Maturity Models
- Ad-hoc
- Repeatable
- Defined
- Managed
- Optimised
Organisations must progress through maturity to reduce systemic risk.
Summary
Security governance aligns technology, people, and processes into a coherent, accountable system.
– Empowering Learners with Cybersecurity Expertise –
ยฉ 2026 All Rights Reserved. Designed with WordPress.
