Chapter 5 of 514% of exam

Governance, Risk, and Compliance

This chapter covers the policies, risk decisions, and legal obligations that steer a security program. You will learn risk management responses, key regulations and standards, and the agreements and frameworks that formalize expectations. Governance aligns security with business objectives and legal requirements.

Policies and Governance

Written policies set expectations and provide the authority to enforce security. A governance program assigns ownership and ensures security supports business goals.

Acceptable use policy
Defines permitted and prohibited use of systems; users acknowledge it as a condition of access.
Security policies
Establish high-level rules, supported by standards, procedures, and guidelines for implementation.
Roles and ownership
Assign data owners, custodians, and processors so accountability is clear.
Security awareness training
Teaches users to recognize phishing and follow policy, reducing human-related risk.
Governance frameworks
The NIST Cybersecurity Framework structures activities into Identify, Protect, Detect, Respond, and Recover.

Risk Management

Risk management identifies, measures, and treats risk within the organization's tolerance. Quantifying risk supports rational decisions about where to spend on controls.

Risk responses
Mitigate, transfer, avoid, or accept each risk based on cost and impact.
Risk transference
Shift financial impact to a third party, commonly through insurance or contracts.
Quantitative analysis
SLE times ARO yields ALE, the expected yearly loss, guiding control spending.
Residual risk
What remains after controls; management must formally acknowledge and accept it.
Risk appetite
The amount of risk leadership is willing to accept, guiding treatment decisions.

Regulations and Standards

Organizations must comply with laws and standards governing sensitive data. Non-compliance can bring fines, liability, and reputational harm.

GDPR
Protects personal data of EU residents with consent, breach notification, and data subject rights.
HIPAA
Safeguards protected health information for US healthcare entities and their associates.
PCI DSS
A contractual standard for securing payment card data; not a law but widely enforced.
Data classification
Label data by sensitivity so appropriate controls and handling apply.
Data retention
Keep data only as long as required by law and business need, then dispose of it securely.

Agreements and Continuity

Contracts formalize expectations with third parties, and continuity planning prepares for disruption. These agreements and plans reduce risk from partners and outages.

Service level agreement
Specifies measurable commitments like uptime and response times with consequences.
Non-disclosure agreement
Legally binds parties to keep shared confidential information secret.
MOU and BPA
Memoranda of understanding and business partnership agreements define cooperation and responsibilities.
Business impact analysis
Identifies critical functions and disruption impact to set RTO and RPO priorities.
Business continuity and disaster recovery
Plans keep operations running and restore systems after major incidents.
Test your knowledge
Practice questions on Governance, Risk, and Compliance
Practice now →

Last updated: July 2026

Report