MODULE 10 โ€” Introduction to Security Governance

Learning Objectives

Learners will:

  1. Understand the role of policies, standards, and procedures.
  2. Explain compliance frameworks (ISO 27001, NIST).
  3. Evaluate governance structures for organisations.
  4. Apply governance principles to risk management.

Module Overview

Governance ensures cybersecurity is not merely technical but organisational. This module introduces frameworks that guide decision-making, accountability, and compliance.


1. Governance Components

  • Policies โ€” leadership intent
  • Standards โ€” mandatory requirements
  • Procedures โ€” operational steps
  • Guidelines โ€” optional best practices

2. Frameworks

2.1 ISO 27001

International standard for information security management.

2.2 NIST CSF

Framework built around identifyโ€“protectโ€“detectโ€“respondโ€“recover.

2.3 COBIT

Governance for enterprise IT.


3. Security Roles

  • CISO
  • Security engineers
  • Governance & risk managers
  • Internal auditors

4. Maturity Models

  • Ad-hoc
  • Repeatable
  • Defined
  • Managed
  • Optimised

Organisations must progress through maturity to reduce systemic risk.


Summary

Security governance aligns technology, people, and processes into a coherent, accountable system.


Cybersecurity CENTRALS

– Empowering Learners with Cybersecurity Expertise –

ยฉ 2026 All Rights Reserved. Designed with WordPress.

Pages: 1 2 3 4 5 6 7 8 9 10