CISM · Domain 1
Information Security Governance
About 17% of the exam
Governance versus management
- Governance
- sets direction, evaluates, monitors
- Management
- plans, builds, runs, reports
- Board
- owns governance, ultimate accountability
- Executives
- set appetite, approve policy, fund
- Security manager
- designs and runs the program
- Oversight
- reporting, assurance, independent review
Governance decides what and why; management decides how and delivers it
Strategy alignment
- Security strategy follows business objectives
- Start from the enterprise strategic plan
- Understand the risk environment first
- Three to five year planning horizon
- Objectives written SMART, tracked by KPIs
- Compliance is a floor, not the goal
- Enable the business, never just restrict
- Review when the business direction shifts
Who does what
- Board of directors
- oversight, appetite, ultimate accountability
- Senior management
- sponsor, fund, accept residual risk
- Steering committee
- cross-functional priorities and alignment
- CISO
- strategy, program, advice, reporting
- Information owner
- classifies, sets access, accepts risk
- Custodian
- operates controls the owner requires
- Internal audit
- independent assurance, reports to board
- Users
- follow policy, report incidents
RACI and the steering committee
- Steering committee brings business unit heads together
- Resolves priority conflicts across functions
- Sponsors initiatives, reviews progress and metrics
- Chaired by an executive, not by IT
- Responsible
- does the work
- Accountable
- answers for the outcome, one only
- Consulted
- gives input before the decision
- Informed
- told after the decision
Exactly one Accountable per activity; many Responsible is fine
Building the strategy
- Business objectives
- Current state
- Desired state
- Gap analysis
- Roadmap
- Measure and adjust
- Current state
- maturity assessment, risk assessment, audit findings
- Desired state
- target maturity tied to objectives
- Gap analysis
- the difference the roadmap closes
- Roadmap
- time-phased initiatives with owners
- Constraints
- budget, culture, law, skills, time
- Review triggers
- merger, cloud move, new regulation, incident
Strategy is the destination, the roadmap is the route, the program is the vehicle
The business case
- Problem statement first, solution second
- Costs, benefits, risk reduction, alternatives
- Speak in business terms, not technical
- Quantify losses avoided and value created
- Include the cost of doing nothing
- Change management cost is usually underestimated
- Executive sponsor before the funding request
Risk reduction plus business value wins the budget; fear does not
Appetite, tolerance, capacity
- Risk appetite
- amount the board chooses to pursue
- Risk tolerance
- acceptable variance around appetite
- Risk capacity
- maximum loss the organization survives
- Risk profile
- the current exposure snapshot
- Residual risk
- what is left, someone must accept
Appetite is set by the board and written down; security measures against it, never sets it
Policy hierarchy
- Policy
- Standard
- Procedure
- Guideline
- Policy approved by senior management, not IT
- Policy follows strategy, standards follow policy
- Review on a cycle and after major change
- Unenforced policy is only a suggestion
- Policy
- management intent, high level, mandatory
- Standard
- specific mandatory requirement or setting
- Procedure
- step by step instructions
- Baseline
- minimum configuration every system meets
- Guideline
- recommended, discretionary
- Exception
- formal, time-bound, risk accepted by owner
Frameworks to name
- COBIT
- enterprise IT governance and management
- ISO 27001
- certifiable ISMS requirements
- ISO 27002
- control implementation guidance
- NIST CSF
- govern, identify, protect, detect, respond, recover
- NIST SP 800-53
- control catalog
- ITIL
- IT service management
- Balanced scorecard
- financial, customer, process, learning views
- CMMI
- maturity levels one to five
Governance outcomes
- Strategic alignment with business goals
- Risk management to acceptable levels
- Value delivery, security investments optimized
- Resource management, knowledge and infrastructure used well
- Performance measurement against defined objectives
- Assurance process integration, no duplicated effort
Six outcomes: alignment, risk, value, resources, performance, assurance
Legal, regulatory, contractual drivers
- Identify every applicable obligation first
- Map requirements to controls once, satisfy many
- Most stringent rule wins across jurisdictions
- Contracts bind suppliers to your standards
- Legal counsel interprets, security implements
- Non-compliance is a business risk, treat it so
- Due care: act as a prudent manager would
Governance metrics
- KGI
- was the goal achieved
- KPI
- how well the process performs
- KRI
- early warning risk is rising
- Maturity level
- capability, not compliance
- Board metric
- business risk posture, trends, value
- Operational metric
- volumes and times, for managers
Good governance metrics link straight to a business objective
Rapid recall: the FIRST move
- Understand business objectives before anything
- Assess impact before proposing a fix
- Check the policy before the technology
- Consult the business owner, then decide
- Gain senior management support first
- Obtain appetite statements before treating risk
- Report through governance channels, not around them
Know the order
- Business strategy
- Security strategy
- Policy
- Standards
- Procedures
- Controls
- Strategy drives policy, never the reverse
- Program implements what the strategy defines
- Metrics close the loop back to strategy
Reference strip: roles, documents, frameworks
Roles
- Board: oversight and appetite
- Executives: sponsor, fund, accept risk
- Steering committee: cross-functional priorities
- CISO: strategy, program, reporting
- Owner classifies, custodian operates
Governance documents
- Strategy, roadmap, program charter
- Policy, standard, procedure, guideline
- Risk appetite statement
- RACI matrix for security activities
- Business case and gap analysis
Frameworks
- COBIT for IT governance
- ISO 27001 and ISO 27002
- NIST CSF and SP 800-53
- ITIL for service management
- Balanced scorecard and CMMI
Six governance outcomes
- Strategic alignment with the business
- Risk management to acceptable levels
- Value delivery from investments
- Resource management done efficiently
- Performance measurement and reporting
- Assurance process integration
Words the exam favors
- Alignment, enablement, accountability
- Senior management support
- Business impact, business objectives
- Culture, tone at the top
- Due care and due diligence
Quick exam traps
- Trap: The CISO sets the organization's risk appetite
- Trap: Compliance with regulation equals adequate security
- Trap: Security policy should be written and approved by IT
- Trap: A business case is won by describing threats in technical detail
- Trap: Governance and management are the same activity at different levels
- Trap: Several people can be Accountable for one activity
- Trap: The steering committee should be chaired by the security manager
- Trap: A good strategy stays fixed for its whole planning horizon
cybercertprep.com · original revision sheet written from the public body of knowledge