Security Governance
Regulations, Standards & Legislation
Wiki topics:
⚖️ · Law & Justice
Security Governance
Regulations, Standards & Legislation
- Purpose: Ensure organizations follow cybersecurity laws, standards, and best practices.
- Due Diligence: Legal obligation to act responsibly and not be negligent.
- Important Laws:
- SOX (Sarbanes-Oxley): Requires risk assessments, internal controls, audits.
- Computer Security Act (1987): Federal agencies must create security policies.
- FISMA (2002): Manages security for federal data systems.
- GDPR: European privacy law — personal data can’t be collected, used, or stored without consent. Applies globally if dealing with EU citizens’ data.
- Other US Laws:
- GLBA: For financial institutions.
- HIPAA: For healthcare data security.
ISO and Cloud Frameworks
- ISO 27000 Series (27k): International info security standards.
- 27001: Main standard, must be purchased.
- 27002: Security controls.
- 27017/27018: Cloud-specific security and privacy.
- 27701: Personal data and privacy management.
- ISO 31000 (31k): Enterprise Risk Management (ERM) — includes financial, legal, and customer risks.
- Cloud Security Alliance (CSA):
- Security Guidance: Adapting on-prem security for the cloud.
- Enterprise Reference Architecture: Tools/methods for secure cloud design.
- Cloud Controls Matrix: Lists cloud security controls.
- SSAE (Attestation Audits):
- SOC 2: Checks internal controls for data security (Type 1 = design, Type 2 = effectiveness).
- SOC 3: Public-friendly summary of SOC 2.
Governance Structure
- Enterprise Governance: Directs and controls the org; defines roles/responsibilities.
- Roles:
- Board of Directors: Set security goals, funding, provide oversight.
- Executive Management: Manage risks, budget, compliance, performance.
- Security Steering Committee: Aligns security with business, manages security budget.
- CISO: Responsible for success/failure of the security program.
- Support Roles:
- Privacy Officer: Manages privacy programs.
- Compliance Officer: Tracks legal/regulatory requirements.
- Physical Security Officer: Handles physical protection measures.
- Internal Audit: Provides independent assurance.
- Functional Roles:
- Owners: Set access and protection rules.
- Custodians: Maintain and monitor security controls.
- Users: Follow security policies.
Governance Documents
- Purpose: Communicate rules, expectations, and direction.
- Types:
- Policy: High-level rules to protect information (CIA). Approved by leadership.
- Standards: Mandatory details for policy enforcement.
- Baselines: Standard collection for specific systems/devices.
- Guidelines: Optional advice to follow standards.
- Procedures: Step-by-step instructions.
- Types: Simple steps, hierarchical, graphic, flowchart.
- Plan: Strategy or action outline, time-based with defined resources.
- Special Documents:
- AUP (Acceptable Use Policy): Lists user rules and responsibilities.
- NDA (Non-Disclosure Agreement): Prevents data leaks, defines data ownership.
- AUP Agreement: User agrees to follow the AUP before getting access.
Change Management
- Goal: Reduce business risk and impact from changes.
- Types of Changes:
- Standard: Routine, low-risk (e.g., patches).
- Normal: Not routine, needs approval (e.g., antivirus change).
- Major: High risk/cost (e.g., new OS).
- Emergency: Urgent, no time for full approval (e.g., backup server activation).
- KPIs (Key Performance Indicators):
- Successful Changes: More is better.
- Change Backlog: Should shrink.
- Emergency Changes: Should not increase.
Configuration Management
- Goal: Keep system configurations consistent, secure, and trusted.
- Elements:
- Configuration Item (CI): Group of related system parts.
- Baseline Configuration (BC): Approved settings, only changeable via process.
- Automated Provisioning:
- Reduces manual work and errors.
- Demand-Based Allocation: Adds/removes resources automatically.
- Idempotence: Scripts produce same result every time.
- Immutable Systems: Don’t change — replace if needed.
- Infrastructure as Code: Code manages and automates infrastructure.
Scripting, Automation & Orchestration
- Scripting: Automates repetitive tasks using:
- Python: Easy to use; powerful for attacks and tools.
- PowerShell: Windows scripting for automation and payloads.
- Bash: Unix/Linux scripting; used for local and remote tasks.
- Macros: Automate inputs; can carry viruses.
- Automation: Runs tasks with no human help — reduces error and boosts speed.
- Orchestration: Coordinates multiple tasks/systems into a larger process.
메타데이터
- post_id
- 5bf3aab69f36
- slug
- security-governance-5bf3aab69f36
- url
- https://medium.com/@kiranmenon16/security-governance-5bf3aab69f36
- canonical_url
- https://medium.com/@kiranmenon16/security-governance-5bf3aab69f36
- author_url
- https://medium.com/@kiranmenon16
- status
- ok
- fetched_at
- 2026-08-12 03:23:28