- 14 more key points in Pro version
- 9 more common mistakes in Pro version
- 5 more exam tips in Pro version
- 31 more related questions in Pro version
Summary
Governance makes security a business responsibility rather than a purely technical function. The information security strategy must support enterprise objectives, fit organizational culture, satisfy applicable obligations, and operate through clearly defined authority and accountability. Senior management sets direction and risk appetite; business and risk owners make business-risk decisions; the security manager advises, enables, measures, and reports. Frameworks, policies, metrics, budgets, and business cases should all trace back to business value and risk reduction.
Key Points
- Governance sets direction, accountability, and oversight; management executes within that direction.
Common Mistakes
- Treating governance as an IT or security-department responsibility only.
Exam Tips
- CISM thinks top-down: business goals -> governance -> strategy -> program -> controls.