chapter four

4 Understanding Governance Processes and Elements

 

This chapter covers

  • Governance elements in cybersecurity
  • Regulations and laws
  • Standards, Policies, and Procedures

Every organization has a purpose, whether it is to provide essential products or specialized services. Achieving this purpose requires consistent decision-making and coordinated action throughout the organization. Without structure, decisions may become inconsistent, and efforts may not align with the organization’s goals. This is where governance comes in.

Governance is the system by which an organization is directed and controlled. It defines how decisions are made, who is responsible for making them, and how those decisions are monitored.

In the context of information systems, IT governance ensures that technology supports the strategy. Governance is implemented through governance frameworks, which provide the necessary structure to guide the organization. These frameworks include elements such as leadership, organizational roles, business processes, standards, and compliance mechanisms.

When applied to cybersecurity, governance ensures that security activities are aligned with business goals, adhere to legal and regulatory requirements, and address risks in a structured manner.

4.1 Understanding Governance Frameworks

4.2 Key Building Blocks of Governance

4.2.1 Laws and Regulations

4.2.2 Standards

4.2.3 Policies

4.2.4 Procedures

4.2.5 Guidelines

4.3 Important Laws and Regulations you Should Know

4.3.1 General Data Protection Regulation (GDPR)

4.3.2 Health Insurance Portability and Accountability Act (HIPAA)

4.3.3 Gramm-Leach-Bliley Act (GLBA)

4.3.4 Closing Thoughts

4.4 Summary

4.5 Review Questions

4.6 Answers to Review Questions