← Back to list

Security Governance

Regulations, Standards & Legislation

HackdMenon · 2026-08-10 06:50 · 0 claps · 2.1 min read
#iso-and-cloud-frameworks #governance-structure #regulation #standards #legislation
Open on Medium ↗
Wiki topics: ⚖️ · Law & Justice

Security Governance

Regulations, Standards & Legislation

  • Purpose: Ensure organizations follow cybersecurity laws, standards, and best practices.
  • Due Diligence: Legal obligation to act responsibly and not be negligent.
  • Important Laws:
  • SOX (Sarbanes-Oxley): Requires risk assessments, internal controls, audits.
  • Computer Security Act (1987): Federal agencies must create security policies.
  • FISMA (2002): Manages security for federal data systems.
  • GDPR: European privacy law — personal data can’t be collected, used, or stored without consent. Applies globally if dealing with EU citizens’ data.
  • Other US Laws:
  • GLBA: For financial institutions.
  • HIPAA: For healthcare data security.

ISO and Cloud Frameworks

  • ISO 27000 Series (27k): International info security standards.
  • 27001: Main standard, must be purchased.
  • 27002: Security controls.
  • 27017/27018: Cloud-specific security and privacy.
  • 27701: Personal data and privacy management.
  • ISO 31000 (31k): Enterprise Risk Management (ERM) — includes financial, legal, and customer risks.
  • Cloud Security Alliance (CSA):
  • Security Guidance: Adapting on-prem security for the cloud.
  • Enterprise Reference Architecture: Tools/methods for secure cloud design.
  • Cloud Controls Matrix: Lists cloud security controls.
  • SSAE (Attestation Audits):
  • SOC 2: Checks internal controls for data security (Type 1 = design, Type 2 = effectiveness).
  • SOC 3: Public-friendly summary of SOC 2.

Governance Structure

  • Enterprise Governance: Directs and controls the org; defines roles/responsibilities.
  • Roles:
  • Board of Directors: Set security goals, funding, provide oversight.
  • Executive Management: Manage risks, budget, compliance, performance.
  • Security Steering Committee: Aligns security with business, manages security budget.
  • CISO: Responsible for success/failure of the security program.
  • Support Roles:
  • Privacy Officer: Manages privacy programs.
  • Compliance Officer: Tracks legal/regulatory requirements.
  • Physical Security Officer: Handles physical protection measures.
  • Internal Audit: Provides independent assurance.
  • Functional Roles:
  • Owners: Set access and protection rules.
  • Custodians: Maintain and monitor security controls.
  • Users: Follow security policies.

Governance Documents

  • Purpose: Communicate rules, expectations, and direction.
  • Types:
  • Policy: High-level rules to protect information (CIA). Approved by leadership.
  • Standards: Mandatory details for policy enforcement.
  • Baselines: Standard collection for specific systems/devices.
  • Guidelines: Optional advice to follow standards.
  • Procedures: Step-by-step instructions.
  • Types: Simple steps, hierarchical, graphic, flowchart.
  • Plan: Strategy or action outline, time-based with defined resources.
  • Special Documents:
  • AUP (Acceptable Use Policy): Lists user rules and responsibilities.
  • NDA (Non-Disclosure Agreement): Prevents data leaks, defines data ownership.
  • AUP Agreement: User agrees to follow the AUP before getting access.

Change Management

  • Goal: Reduce business risk and impact from changes.
  • Types of Changes:
  • Standard: Routine, low-risk (e.g., patches).
  • Normal: Not routine, needs approval (e.g., antivirus change).
  • Major: High risk/cost (e.g., new OS).
  • Emergency: Urgent, no time for full approval (e.g., backup server activation).
  • KPIs (Key Performance Indicators):
  • Successful Changes: More is better.
  • Change Backlog: Should shrink.
  • Emergency Changes: Should not increase.

Configuration Management

  • Goal: Keep system configurations consistent, secure, and trusted.
  • Elements:
  • Configuration Item (CI): Group of related system parts.
  • Baseline Configuration (BC): Approved settings, only changeable via process.
  • Automated Provisioning:
  • Reduces manual work and errors.
  • Demand-Based Allocation: Adds/removes resources automatically.
  • Idempotence: Scripts produce same result every time.
  • Immutable Systems: Don’t change — replace if needed.
  • Infrastructure as Code: Code manages and automates infrastructure.

Scripting, Automation & Orchestration

  • Scripting: Automates repetitive tasks using:
  • Python: Easy to use; powerful for attacks and tools.
  • PowerShell: Windows scripting for automation and payloads.
  • Bash: Unix/Linux scripting; used for local and remote tasks.
  • Macros: Automate inputs; can carry viruses.
  • Automation: Runs tasks with no human help — reduces error and boosts speed.
  • Orchestration: Coordinates multiple tasks/systems into a larger process.

메타데이터
post_id
5bf3aab69f36
slug
security-governance-5bf3aab69f36
url
https://medium.com/@kiranmenon16/security-governance-5bf3aab69f36
canonical_url
https://medium.com/@kiranmenon16/security-governance-5bf3aab69f36
author_url
https://medium.com/@kiranmenon16
status
ok
fetched_at
2026-08-12 03:23:28