Governance, Risk, and Compliance
This chapter covers the policies, risk decisions, and legal obligations that steer a security program. You will learn risk management responses, key regulations and standards, and the agreements and frameworks that formalize expectations. Governance aligns security with business objectives and legal requirements.
Policies and Governance
Written policies set expectations and provide the authority to enforce security. A governance program assigns ownership and ensures security supports business goals.
Risk Management
Risk management identifies, measures, and treats risk within the organization's tolerance. Quantifying risk supports rational decisions about where to spend on controls.
Regulations and Standards
Organizations must comply with laws and standards governing sensitive data. Non-compliance can bring fines, liability, and reputational harm.
Agreements and Continuity
Contracts formalize expectations with third parties, and continuity planning prepares for disruption. These agreements and plans reduce risk from partners and outages.
Last updated: July 2026