Summarize elements of effective security governance
Guidelines, policies, standards, procedures, governance structures, and roles like owner, custodian, processor.
- Reading time
- 20 min read
- Flashcards
- 18 cards
- Practice questions
- 8 questions · 2 PBQs
Domain 5 is the paperwork domain, and people underestimate it — it is 20% of the exam and almost entirely recall. This objective is about the documents an organisation writes and who is accountable for what.
The document hierarchy
The single most tested thing here. Four levels, from most to least binding:
Policy
- High-level statement of intent
- MANDATORY
- 'All data must be encrypted at rest'
Standard
- Specific mandatory requirement
- MANDATORY
- 'Use AES-256'
Procedure
- Step-by-step instructions
- MANDATORY
- 'To enable encryption: click...'
Guideline
- Recommended practice
- OPTIONAL
- 'Consider rotating keys annually'
The tellPolicy says WHAT and WHY. Standard says the specific requirement. Procedure says HOW, step by step. Guideline is advice you may ignore.
Check yourself
A document states 'All portable devices must use full-disk encryption.' Which type is it?
The policies CompTIA names
- Acceptable use policy (AUP) — what users may and may not do with company systems.
- Information security policies — the overarching security requirements.
- Business continuity — keeping the business running during disruption.
- Disaster recovery — restoring IT systems after a disaster.
- Incident response — see 4.8.
- Software development lifecycle (SDLC) — security built into development.
- Change management — see 1.3.
Business continuity vs disaster recovery is a tested pair: BC keeps the business operating; DR restores technology. BC is broader and includes DR.
Standards and procedures
Standards CompTIA lists: password, access control, physical security, encryption.
Procedures: change management, onboarding/offboarding, and playbooks — the step-by-step response guides used in a SOC.
Governance structures
Board
The highest level of organisational oversight, ultimately accountable.
Committee
A group focused on a specific area, such as a security steering committee.
Government entity
Regulators and public bodies imposing external requirements.
Centralised governance
- Decisions made in one place
- Consistent, easier to audit
- Slower, less responsive locally
Decentralised governance
- Decisions made by business units
- Faster, locally relevant
- Inconsistent, harder to audit
The tellConsistency versus responsiveness. Neither is correct in the abstract — the exam asks which fits the described organisation.
Roles and responsibilities
Frequently tested, and the controller/processor pair especially.
Data owner
Accountable for the data. Decides classification and who may access it. A senior business role, not a technical one.
Data controller
Determines why and how personal data is processed. Bears the legal responsibility under privacy law.
Data processor
Processes data on behalf of the controller, following their instructions. A cloud provider is typically a processor.
Data custodian / steward
Handles day-to-day protection — backups, access implementation, technical safeguards. Implements what the owner decides.
Check yourself
A retailer uses a cloud email provider to handle customer communications. Which role does the retailer hold?
The data subject is the individual the personal data is about — the customer, not the company.
External considerations
Requirements imposed from outside: regulatory, legal, industry, and geographic — local/regional, national, global. An organisation operating in several jurisdictions may face conflicting requirements, which is why data sovereignty (3.3) matters.
Monitoring and revision
Governance documents are not written once. They are monitored for effectiveness and revised as the business, threats and regulations change. A policy nobody has reviewed in six years is a compliance finding waiting to happen.