- Published on
Cybersecurity – Governance, Compliance & Security Management
Question 1: What is security governance?
Answer:
Security governance is the framework of policies, procedures, and controls that directs and manages an organization’s cybersecurity program. It ensures that security activities support business objectives while protecting organizational assets.
Question 2: Why is security governance important?
Answer:
Security governance helps organizations:
Question 3: What is the difference between centralized and decentralized governance?
Answer:
Centralized Governance
Question 4: What is a policy framework?
Answer:
A policy framework is a collection of documents that define how an organization manages information security. It consists of:
Question 5: What is a security policy?
Answer:
A security policy is a high-level statement issued by management that defines the organization’s security objectives, expectations, and overall direction.
It explains what the organization expects employees and systems to achieve.
Question 6: What are security standards?
Answer:
Security standards specify the mandatory technical or operational requirements that must be followed to support security policies. They ensure consistency across the organization.
Question 7: What are security procedures?
Answer:
Security procedures are detailed, step-by-step instructions describing how to perform specific security tasks correctly and consistently.
Question 8: What are security guidelines?
Answer:
Security guidelines are recommended best practices that help employees implement security controls effectively. Unlike policies, standards, and procedures, guidelines are optional rather than mandatory.
Question 9: What are some common security policies used by organizations?
Answer:
Organizations commonly implement policies such as:
Question 10: Why should security policies include an exception process?
Answer:
An exception process allows approved deviations from security policies when business needs require them. It ensures exceptions are properly reviewed, documented, approved, and protected by compensating controls to reduce any additional risk.
Question 11: What is change management?
Answer:
Change management is a structured process used to review, approve, test, implement, and document changes made to systems, applications, or infrastructure. Its primary purpose is to reduce the risk of unexpected outages or disruptions.
Question 12: Why is change management important?
Answer:
Change management helps organizations:
Question 13: What are security compliance requirements?
Answer:
Security compliance requirements are legal, regulatory, or industry obligations that organizations must follow to protect information and operate responsibly.
Common examples include:
Question 14: What are cybersecurity frameworks?
Answer:
Cybersecurity frameworks provide structured guidance for building, evaluating, and improving an organization’s security program.
Common frameworks include:
Question 15: What is the difference between security training and security awareness?
Answer:
Security Training
Key Points to Remember
Governance Models
Centralized Governance
Policy Framework
Policy
Common Organizational Policies
Compliance Requirements
Common Cybersecurity Frameworks
Security Education
Training
Memory Trick
PSPG = Policy Framework
Question 1: What is security governance?
Answer:
Security governance is the framework of policies, procedures, and controls that directs and manages an organization’s cybersecurity program. It ensures that security activities support business objectives while protecting organizational assets.
Question 2: Why is security governance important?
Answer:
Security governance helps organizations:
- Align security with business goals.
- Establish clear responsibilities.
- Improve decision-making.
- Manage cybersecurity risks.
- Meet legal and regulatory requirements.
- Strengthen overall security management.
Question 3: What is the difference between centralized and decentralized governance?
Answer:
Centralized Governance
- Uses a top-down management approach.
- Senior leadership makes security decisions.
- All departments follow the same security requirements.
- Provides consistent security across the organization.
- Gives departments or business units authority to implement security controls.
- Each department determines how to achieve organizational security goals.
- Offers greater flexibility but may lead to differences in security practices.
Question 4: What is a policy framework?
Answer:
A policy framework is a collection of documents that define how an organization manages information security. It consists of:
- Policies
- Standards
- Procedures
- Guidelines
Question 5: What is a security policy?
Answer:
A security policy is a high-level statement issued by management that defines the organization’s security objectives, expectations, and overall direction.
It explains what the organization expects employees and systems to achieve.
Question 6: What are security standards?
Answer:
Security standards specify the mandatory technical or operational requirements that must be followed to support security policies. They ensure consistency across the organization.
Question 7: What are security procedures?
Answer:
Security procedures are detailed, step-by-step instructions describing how to perform specific security tasks correctly and consistently.
Question 8: What are security guidelines?
Answer:
Security guidelines are recommended best practices that help employees implement security controls effectively. Unlike policies, standards, and procedures, guidelines are optional rather than mandatory.
Question 9: What are some common security policies used by organizations?
Answer:
Organizations commonly implement policies such as:
- Information Security Policy
- Acceptable Use Policy (AUP)
- Data Ownership Policy
- Data Retention Policy
- Account Management Policy
- Password Policy
Question 10: Why should security policies include an exception process?
Answer:
An exception process allows approved deviations from security policies when business needs require them. It ensures exceptions are properly reviewed, documented, approved, and protected by compensating controls to reduce any additional risk.
Question 11: What is change management?
Answer:
Change management is a structured process used to review, approve, test, implement, and document changes made to systems, applications, or infrastructure. Its primary purpose is to reduce the risk of unexpected outages or disruptions.
Question 12: Why is change management important?
Answer:
Change management helps organizations:
- Prevent service interruptions.
- Reduce implementation errors.
- Ensure changes are properly tested.
- Maintain accurate documentation.
- Minimize operational risks.
- Improve system availability and reliability.
Question 13: What are security compliance requirements?
Answer:
Security compliance requirements are legal, regulatory, or industry obligations that organizations must follow to protect information and operate responsibly.
Common examples include:
- PCI DSS for payment card information.
- GDPR for protecting the personal information of individuals in the European Union.
- National, regional, and state cybersecurity or privacy laws.
Question 14: What are cybersecurity frameworks?
Answer:
Cybersecurity frameworks provide structured guidance for building, evaluating, and improving an organization’s security program.
Common frameworks include:
- NIST Cybersecurity Framework (CSF)
- NIST Risk Management Framework (RMF)
- ISO security standards
Question 15: What is the difference between security training and security awareness?
Answer:
Security Training
- Provides employees with new knowledge and practical skills.
- Is tailored to an individual’s job responsibilities.
- Helps employees perform their duties securely.
- Reinforces previously learned security concepts.
- Reminds employees of their ongoing security responsibilities.
- Encourages safe security habits and reduces human error.
Key Points to Remember
Governance Models
Centralized Governance
- Top-down decision making.
- Standardized security practices.
- Managed by senior leadership.
- Decision making is delegated to departments.
- Greater operational flexibility.
- Security implementation may differ between business units.
Policy Framework
Policy
- High-level management direction.
- Mandatory.
- Specific implementation requirements.
- Mandatory.
- Step-by-step instructions.
- Mandatory.
- Recommended best practices.
- Optional.
Common Organizational Policies
- Information Security Policy
- Acceptable Use Policy (AUP)
- Data Ownership Policy
- Data Retention Policy
- Account Management Policy
- Password Policy
Compliance Requirements
- PCI DSS
- GDPR
- National cybersecurity laws
- State and regional privacy regulations
Common Cybersecurity Frameworks
- NIST Cybersecurity Framework (CSF)
- NIST Risk Management Framework (RMF)
- ISO Security Standards
Security Education
Training
- Teaches new knowledge and skills.
- Role-specific.
- Reinforces existing knowledge.
- Encourages secure behavior and continuous vigilance.
Memory Trick
PSPG = Policy Framework
- P = Policy → Defines organizational expectations.
- S = Standard → Specifies mandatory requirements.
- P = Procedure → Explains how to perform tasks.
- G = Guideline → Recommends best practices.
0 Comments