Chương 5 / 514% của kỳ thi

Governance, Risk, and Compliance

This chapter covers the policies, risk decisions, and legal obligations that steer a security program. You will learn risk management responses, key regulations and standards, and the agreements and frameworks that formalize expectations. Governance aligns security with business objectives and legal requirements.

Policies and Governance

Governance provides the structure, authority, and accountability that make a security program more than a collection of tools, and SY0-701 expects you to know how policies, standards, procedures, and guidelines fit together. Policies are high-level statements of intent approved by leadership; standards are the specific, mandatory requirements that support them, such as a minimum password length; procedures are step-by-step instructions; and guidelines are recommended but non-mandatory best practices. Common policies you should recognize include the acceptable use policy, which defines permitted and prohibited use of systems and which users acknowledge as a condition of access; information security policies; business continuity and disaster recovery policies; incident response policy; change management policy; and software development lifecycle policy. Governance also defines who is in charge, through structures such as boards, committees, and clear governance models, and through data roles: the data owner holds overall accountability for a data set, the data controller determines how and why data is processed, the data processor acts on the controller's behalf, the data custodian manages storage and technical protection, and the data steward oversees quality and appropriate use. Assigning these roles makes accountability explicit. Security awareness training teaches users to recognize phishing and social engineering, follow policy, handle data properly, and report incidents, reducing the human risk that technology cannot fully address; effective programs run continuously, use simulated phishing, and tailor content to roles such as executives and developers. Governance frameworks give programs a proven structure: the NIST Cybersecurity Framework organizes activities into Identify, Protect, Detect, Respond, and Recover, while standards like the ISO 27000 series, COBIT, and control catalogs such as NIST SP 800-53 and the CIS Controls provide benchmarks to build and measure against. External considerations shape governance too, including regulatory, legal, industry, and geographic factors, along with monitoring and revision so that policies stay current as the business and threat landscape change. Ultimately governance aligns security with business objectives, ensures decisions are made by the right people with the right authority, and creates the documented basis needed to enforce controls and demonstrate diligence to regulators, customers, and partners.

Acceptable use policy
Defines permitted and prohibited use of systems; users acknowledge it as a condition of access.
Security policies
Establish high-level rules, supported by standards, procedures, and guidelines for implementation.
Roles and ownership
Assign data owners, custodians, and processors so accountability is clear.
Security awareness training
Teaches users to recognize phishing and follow policy, reducing human-related risk.
Governance frameworks
The NIST Cybersecurity Framework structures activities into Identify, Protect, Detect, Respond, and Recover.

Risk Management

Risk management identifies, measures, and treats risk within the organization's tolerance, giving leaders a rational basis for deciding where to spend limited resources. The process begins with risk identification and a risk assessment, which may be ad hoc, recurring, one-time, or continuous, and produces a risk register that records each risk along with its owner, likelihood, impact, and treatment. Risk analysis can be qualitative, ranking risks with descriptive scales like high, medium, and low, or quantitative, assigning dollar figures. The quantitative formulas are a favorite exam target: the single loss expectancy equals the asset value multiplied by the exposure factor, the annualized rate of occurrence is how many times per year the event is expected, and their product, SLE times ARO, gives the annualized loss expectancy, the expected yearly loss that justifies control spending. Key risk indicators and risk appetite, the amount of risk leadership is willing to accept, guide how aggressively risks are treated. Once a risk is understood, the organization chooses a response: mitigate by applying controls that reduce likelihood or impact, transfer by shifting financial impact to a third party such as through insurance or contractual terms, avoid by ceasing the risky activity, or accept by acknowledging the risk and taking no further action, sometimes with formal exemptions or exceptions. After controls are applied, residual risk remains, and management must formally acknowledge and accept it; control risk and inherent risk are related concepts the exam may reference. Risk reporting communicates the current posture to stakeholders. A business impact analysis supports these decisions by identifying critical functions and quantifying the effect of their disruption, feeding recovery objectives. Third-party and supply-chain risk deserves special attention: organizations perform vendor due diligence and assessments, use questionnaires and independent audits, monitor vendors over time, and manage risk from hardware suppliers, software providers, and managed service providers. By quantifying and prioritizing risk rather than reacting to the loudest fear, risk management ensures that security investment flows to where it reduces the most expected loss, and that leadership consciously owns the risk that remains.

Risk responses
Mitigate, transfer, avoid, or accept each risk based on cost and impact.
Risk transference
Shift financial impact to a third party, commonly through insurance or contracts.
Quantitative analysis
SLE times ARO yields ALE, the expected yearly loss, guiding control spending.
Residual risk
What remains after controls; management must formally acknowledge and accept it.
Risk appetite
The amount of risk leadership is willing to accept, guiding treatment decisions.

Regulations and Standards

Organizations operate under a web of laws, regulations, and standards that govern how sensitive data is handled, and non-compliance can bring fines, legal liability, and reputational harm. The exam expects familiarity with major regimes even though it does not require legal depth. The General Data Protection Regulation protects the personal data of individuals in the European Union, requiring a lawful basis such as consent, granting data subject rights including access and erasure, mandating breach notification within a set timeframe, and reaching any organization that handles EU residents' data regardless of location. HIPAA safeguards protected health information handled by US healthcare providers, plans, and their business associates, setting privacy and security rules. PCI DSS is a contractual industry standard, not a law, that mandates specific controls for any organization that stores, processes, or transmits payment card data, and it is widely enforced by the card brands. Other references include SOX for financial reporting integrity, GLBA for financial privacy, and regional privacy laws. Compliance is not one-time: organizations perform compliance monitoring, both internal and external, track attestation and acknowledgment, and face consequences for non-compliance that range from fines and sanctions to loss of license and contractual penalties, alongside reputational damage. Underpinning compliance is data governance. Data classification labels information by sensitivity, using schemes such as public, private, sensitive, confidential, restricted, and critical, or governmental levels like unclassified through top secret, so that appropriate handling and controls apply to each tier. Data types the exam names include regulated data, personally identifiable information, protected health information, intellectual property, trade secrets, and financial data. Data states of at rest, in transit, and in use each call for protective controls such as encryption and access restriction. Data sovereignty means data is subject to the laws of the country where it resides, which shapes cloud region choices, and geographic restrictions can limit where data may travel. Data retention keeps information only as long as law and business need require, then disposes of it securely, balancing legal preservation duties against the risk and cost of holding data too long.

GDPR
Protects personal data of EU residents with consent, breach notification, and data subject rights.
HIPAA
Safeguards protected health information for US healthcare entities and their associates.
PCI DSS
A contractual standard for securing payment card data; not a law but widely enforced.
Data classification
Label data by sensitivity so appropriate controls and handling apply.
Data retention
Keep data only as long as required by law and business need, then dispose of it securely.

Agreements and Continuity

Formal agreements set expectations with third parties, and continuity planning prepares the organization to survive disruption, so both reduce risk that originates outside day-to-day operations. SY0-701 expects you to distinguish the common agreement types by purpose. A service level agreement specifies measurable commitments such as uptime percentage, response times, and support levels, with consequences when a provider falls short, and it is the primary tool for holding vendors accountable. A memorandum of understanding, or MOU, is a non-binding statement of intent that outlines how parties will cooperate, while a memorandum of agreement is more formal. A business partnership agreement, or BPA, defines the terms of a partnership including responsibilities and profit sharing. A master service agreement sets overarching terms under which specific statements of work, or SOWs, describe individual engagements and deliverables. A non-disclosure agreement legally binds parties to keep shared confidential information secret, and an interconnection security agreement governs the secure connection between two organizations' systems. Recognizing which agreement fits a scenario, such as choosing an SLA to enforce vendor uptime or an NDA to protect confidential data shared with a contractor, is exactly the discrimination the exam tests. Continuity planning ensures the business can keep operating and recover after a serious disruption. The business impact analysis identifies critical functions and quantifies the impact of their loss over time, setting the priorities and the recovery time and recovery point objectives that drive planning. A business continuity plan focuses on keeping essential operations running during a disruption, often through alternate processes and sites, while a disaster recovery plan focuses on restoring IT systems and data after an event. Continuity of operations planning provides for essential functions when normal facilities are unavailable. These plans must be documented, assigned to owners, communicated, and, above all, tested through tabletop exercises, walkthroughs, simulations, and full failover drills, because a plan that has never been exercised routinely fails when it is finally needed. Together, well-chosen agreements and tested continuity plans extend an organization's risk management beyond its own walls and beyond normal operating conditions.

Service level agreement
Specifies measurable commitments like uptime and response times with consequences.
Non-disclosure agreement
Legally binds parties to keep shared confidential information secret.
MOU and BPA
Memoranda of understanding and business partnership agreements define cooperation and responsibilities.
Business impact analysis
Identifies critical functions and disruption impact to set RTO and RPO priorities.
Business continuity and disaster recovery
Plans keep operations running and restore systems after major incidents.
Kiểm tra kiến thức của bạn
Câu hỏi luyện tập về Governance, Risk, and Compliance
Luyện tập ngay →

Last updated: September 2026

Học theo trình tự?

Luyện tập vẫn miễn phí. Trọn bộ hướng dẫn CompTIA Security+ (SY0-701) là chính phần kiến thức, dạy từ đầu đến cuối — tệp PDF + EPUB tải về, thuộc về bạn.

Nhận sách — $14.99
Báo lỗi