Skip to content
atlas

Governance

Also known as: security governance, information security governance

How leadership steers security - setting direction, handing out responsibility and checking that it works.

Draft - this entry has not been reviewed yet.

Formal

The system by which an organisation's leadership sets security goals, assigns roles and responsibility, decides how much risk is acceptable, and follows up on results.

In plain English

Like the captain of a ship - the crew does the rowing, but someone must choose the course and answer for where the ship ends up.

In practice

The board of a Danish pension fund names a security lead, approves the security policy and asks for a risk report every quarter - and under DORA its members must also take security training themselves.

Why it matters

Without clear steering from the top, security stays a scattered IT task with no budget, no owner and no one to answer when things go wrong.

Technical deep dive

Governance is conventionally separated from management. ISO/IEC 38500 and COBIT 2019 describe the governing body's role as evaluate, direct and monitor, while management plans, builds, runs and monitors within that direction; ISO/IEC 27014:2020 applies the same split to information security. In NIST CSF 2.0 (2024) governance became a sixth function, Govern, placed around the other five, with the categories Organizational Context (GV.OC), Risk Management Strategy (GV.RM), Roles, Responsibilities and Authorities (GV.RR), Policy (GV.PO), Oversight (GV.OV) and Cybersecurity Supply Chain Risk Management (GV.SC).

The central decisions are risk appetite and accountability. Risk appetite is the amount and type of risk the organisation is willing to pursue or retain in pursuit of its objectives; risk tolerance translates it into measurable limits, such as the maximum acceptable downtime for a critical service or the share of critical vulnerabilities older than a set number of days. Accountability is made explicit through named information and system owners, a CISO or security coordinator with a defined reporting line, and decision rights over exceptions and accepted risks. ISO/IEC 27001:2022 clause 5 requires top management to demonstrate leadership, establish the security policy and assign roles, and clause 9.3 requires management review of the ISMS at planned intervals.

Regulation has moved governance from good practice to legal duty. NIS2 Art. 20(1) requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures, oversee their implementation and be liable for infringements, and Art. 20(2) requires members of those bodies to follow training; Art. 32(5) even allows a temporary ban on a person exercising managerial functions in an essential entity. DORA Art. 5 places ultimate responsibility for ICT risk on the management body of financial entities and requires its members to keep their ICT risk knowledge up to date.

Many organisations structure assurance around the Institute of Internal Auditors' Three Lines Model (2020): management owns and operates risk and controls, specialist functions such as security and compliance provide expertise and challenge, and internal audit provides independent assurance to the governing body. Typical failure modes are a CISO reporting several levels below the board through IT, which creates a conflict of interest, risk registers with no one authorised to accept risks, metrics that report activity rather than risk, and boards that receive technical dashboards they cannot act on. Governance differs from risk management, which analyses and treats risks within the appetite governance sets, and from compliance, which checks conformity with external and internal requirements.

Relationships

Sources & further reading

Standards & official texts

  • NIST Cybersecurity Framework (CSF) 2.0 - Govern function · NIST

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.