Information Security Governance and Frameworks
Security is a governance responsibility, not just an IT task. The exam tests who is ultimately accountable, and the difference between a policy, a standard and a procedure.
What this makes you able to do
Evaluate whether information security is governed through a program with defined accountability, a policy hierarchy, and a recognised framework.
By the end you can
- Identify who is ultimately accountable for information security.
- Distinguish a policy from a standard and a procedure.
- Explain the purpose of a security framework such as ISO 27001.
Transcript
Information security governance and frameworks. Domain five is the largest and most technical on the exam, and it opens exactly where Domain two did: with governance. Because protection without direction is just a pile of tools.
Here is the situation. You ask who owns information security, and the answer is, IT does, it’s their systems. The security policy is a two-year-old document nobody has read, there is no distinction between what is mandatory and what is advice, and when a control is missing, each team assumes another was handling it. Security here is treated as a technical chore, not something the organisation governs.
So who is actually accountable. Information security is a governance responsibility. Senior management and the board are ultimately accountable: they set the tone from the top, approve the security policy, and allocate the resources. A security function, often led by a C-I-S-O, and the I-T teams implement and operate the controls, but they do so within a mandate management owns.
This is the same shape as risk appetite in Domain two. When a question asks who is ultimately accountable for security, the answer is not I-T and not the security team; it is senior management. Treating security as purely I-T’s problem is the governance failure that leaves gaps no one owns.
Now the policy hierarchy, because the exam expects you to tell the layers apart. A policy without standards is aspiration with nothing to test against; standards without a policy are rules with no authority behind them. So keep them straight.
First, a policy states management’s high-level intent and direction: information must be protected in line with its classification. It is the mandate.
Second, a standard turns that intent into mandatory, measurable requirements: a minimum encryption strength, a password length, an approved configuration. Standards are not optional.
And third, a procedure gives the step-by-step instructions to meet a standard, while a guideline offers optional advice and good practice. Four layers, each doing a different job.
So the shortcut is: intent, mandatory, how, advice. When a question describes high-level intent, that is a policy. A mandatory specific requirement is a standard. Step by step is a procedure. Optional good practice is a guideline.
Organisations do not invent security from scratch; they adopt recognised frameworks. I-S-O twenty-seven thousand and one defines an information security management system; the NIST Cybersecurity Framework and COBIT are others. Their value is a structured, repeatable way to identify risks, select and apply controls, and monitor and improve them.
And the exam’s angle mirrors compliance in Domain two: a framework is an ongoing management system, not a one-off certificate. Achieving I-S-O twenty-seven thousand and one certification once and never maintaining the system is the same stale-certificate problem in new clothes. And no framework guarantees you cannot be breached; it manages risk, it does not abolish it.
So carry this away. Security is governed by senior management, who are accountable for it, exactly as they are for risk. Policy is intent, standards are mandatory, procedures are the how, and a framework is the ongoing system that holds it all together.
1.Who is ULTIMATELY accountable for information security in an organisation?
2.What is the difference between a security policy and a standard?
3.What is the primary purpose of adopting a framework such as ISO 27001?
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
