Security Governance
Summarize elements of effective security governance
What you will learn
- Separate policy, standard, procedure and guideline by how binding and how detailed each is.
- Name the governance roles and know who owns data, who guards it and who processes it.
- Explain centralised versus decentralised governance and what each costs.
- Know the external considerations that impose policies an organisation does not choose.
Governance is not merely documents; it answers two questions: who decides, and who answers when something goes wrong. What it tests most is telling the document types apart — because the exam describes a text and asks what it is, and the difference is in how binding and how detailed it is, not in the subject.
The four documents
| Policy | Binding and high-level: it says what and why, not how. Approved by senior management. "Customer data must be protected." |
|---|---|
| Standard | Binding and specific: it sets the required measure. "AES-256 encryption; passwords of twelve characters or more." |
| Procedure | Binding and step by step: how the work is done. "To disable a leaver's account: open the system, then…" |
| Guideline | Not binding: a recommendation, a good practice. The key word is "should", not "must". |
A ladder from general to specific
The policy says what, the standard says how much, the procedure says how, and the guideline suggests without binding. If the text names a number or a specific algorithm it is a standard; if it lists numbered steps it is a procedure; if it says "should" it is a guideline.
The roles
| Data owner | The business leader who owns the data and decides its classification and who may access it. Not a technical role. |
|---|---|
| Data custodian / steward | Whoever implements the owner's decision technically: backups, encryption, permissions. They guard; they do not decide. |
| Data controller | The party determining the purpose and means of processing. A regulatory term first and foremost. |
| Data processor | Whoever processes data on the controller's behalf and under its instructions — a cloud provider, for instance. |
Centralised vs decentralised governance
| Centralised | Decentralised | |
|---|---|---|
| Decisions | One body for the whole organisation | Each unit decides for itself |
| Consistency | High | Low — controls may conflict |
| Speed and fit | Slower, and may not fit every unit | Faster and closer to the unit's reality |
Then there are external considerations: not every policy is a choice. Local regulation, legislation, industry standards and contractual requirements all impose controls the organisation does not debate. When a question names a regulatory requirement, that constraint is not something to be weighed against cost.
Real-world example: one subject, four documents
Passwords in one organisation appear in four different documents. The policy: "accounts must be protected by strong authentication" — general, binding, signed by the chief executive. The standard: "at least twelve characters, and multi-factor authentication on every administrative account" — a specific number, binding. The procedure: "to reset a password: verify identity through the line manager, then open the system, then…" — numbered steps. The guideline: "a password manager is recommended" — advice nobody is disciplined for ignoring. An exam question will describe one of these and ask which it is.
What matters on the exam
- A specific number or algorithm = standard. Numbered steps = procedure. A general "must" = policy. "Should" = guideline.
- The data owner is a business role, not a technical one. The custodian implements their decision; they do not make it.
- The controller determines the purpose; the processor acts on its instructions. A cloud provider is usually a processor, not a controller.
- A regulatory requirement is not weighed against cost. If the question names a law, the "accept the risk" option is usually wrong.
Quick check
Answer in your head first, then reveal.
"Disks must be encrypted with AES-256" — policy or standard?Reveal the answer
A standard: it names a specific algorithm and a required measure. The matching policy would say "data at rest must be protected" without naming a tool.
Who classifies a data set: the security manager, or the department head who owns it?Reveal the answer
The data owner — the department head. Security advises and implements controls, but deciding the data's value and sensitivity is a business decision, not a technical one.
What sets a guideline apart from the other three?Reveal the answer
It is not binding. Policy, standard and procedure carry consequences for breach; a guideline is advice to be applied as context allows.
What is the drawback of decentralised governance?Reveal the answer
Conflicting controls and uneven protection between units, so the weakest becomes the organisation's real level. Its benefit is speed and fit; its price is consistency.
Sign in to track your progress on this topic.
Your next step
Read the lesson, then mark it complete
Sources
Used to verify the facts. The writing is original to Passuit.