Governance
Also known as: security governance, information security governance
How leadership steers security - setting direction, handing out responsibility and checking that it works.
Draft - this entry has not been reviewed yet.
Formal
The system by which an organisation's leadership sets security goals, assigns roles and responsibility, decides how much risk is acceptable, and follows up on results.
In plain English
Like the captain of a ship - the crew does the rowing, but someone must choose the course and answer for where the ship ends up.
In practice
The board of a Danish pension fund names a security lead, approves the security policy and asks for a risk report every quarter - and under DORA its members must also take security training themselves.
Why it matters
Without clear steering from the top, security stays a scattered IT task with no budget, no owner and no one to answer when things go wrong.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Have the board decide who is accountable for information security, and appoint a named security lead (CISO or coordinator) with a direct reporting line to top management.
- Write a short information security policy that states goals, scope and roles, and have top management approve and sign it.
- Set the risk appetite, turn it into measurable tolerances such as maximum downtime for critical services, and record who may accept risks and grant exceptions.
- Name owners for the key information assets and systems, and set up a security committee where business and IT meet on a fixed schedule.
- Give the board and management the security training that NIS2 Art. 20 and, in the financial sector, DORA Art. 5 require, and repeat it regularly.
- Agree a small set of risk-based metrics and report them to management every quarter in business language, not as technical dashboards.
- Hold a management review at planned intervals, typically yearly (ISO 27001 clause 9.3), that covers results, audit findings and changes, and records decisions and actions.
- Have internal audit or an external party check independently that the governance set-up works, and follow up on the findings.
Common pitfalls
- Letting the CISO report deep inside IT, so the person who runs the systems also judges their risk.
- Handing security wholly to IT, so no one with authority accepts or funds the risks.
- Reporting activity (courses held, tickets closed) instead of risk and effect.
- A policy approved once and never reviewed again.
Good guides
- NIST CSWP 29 - The NIST Cybersecurity Framework (CSF) 2.0(opens in a new tab) · NIST
- Cyber Security Toolkit for Boards(opens in a new tab) · NCSC UK
- Roller og ansvar(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
- Leder - sikkerdigital.dk(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
Governance is conventionally separated from management. ISO/IEC 38500 and COBIT 2019 describe the governing body's role as evaluate, direct and monitor, while management plans, builds, runs and monitors within that direction; ISO/IEC 27014:2020 applies the same split to information security. In NIST CSF 2.0 (2024) governance became a sixth function, Govern, placed around the other five, with the categories Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV) and Cybersecurity Supply Chain Risk Management (GV.SC).
The central decisions are risk appetite and accountability. Risk appetite is the amount and type of risk the organisation is willing to pursue or retain in pursuit of its objectives; risk tolerance translates it into measurable limits, such as the maximum acceptable downtime for a critical service or the share of critical vulnerabilities older than a set number of days. Accountability is made explicit through named information and system owners, a CISO or security coordinator with a defined reporting line, and decision rights over exceptions and accepted risks. ISO/IEC 27001:2022 clause 5 requires top management to demonstrate leadership, establish the security policy and assign roles, and clause 9.3 requires management review of the ISMS at planned intervals.
Regulation has moved governance from good practice to legal duty. NIS2 Art. 20(1) requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures, oversee their implementation and be liable for infringements, and Art. 20(2) requires members of those bodies to follow training; Art. 32(5) even allows a temporary ban on a person exercising managerial functions in an essential entity. DORA Art. 5 places ultimate responsibility for ICT risk on the management body of financial entities and requires its members to keep their ICT risk knowledge up to date.
Many organisations structure assurance around the Institute of Internal Auditors' Three Lines Model (2020): management owns and operates risk and controls, specialist functions such as security and compliance provide expertise and challenge, and internal audit provides independent assurance to the governing body. Typical failure modes are a CISO reporting several levels below the board through IT, which creates a conflict of interest, risk registers with no one authorised to accept risks, metrics that report activity rather than risk, and boards that receive technical dashboards they cannot act on. Governance differs from risk management, which analyses and treats risks within the appetite governance sets, and from compliance, which checks conformity with external and internal requirements.
Relationships
Sources & further reading
Standards & official texts
- NIST Cybersecurity Framework (CSF) 2.0 - Govern function · NIST
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…