StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 1: Security & risk management

Security governance: alignment with business strategy, roles, due care vs due diligence

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Security governance is the set of structures, responsibilities and processes through which senior leadership directs and controls security. The CISSP exam treats security as a business function, not a technical hobby. The right answer to a governance question is almost always the one that supports the organization's mission, goals and objectives, is sponsored by senior management and flows from the top down. A bottom-up approach, where the IT team decides security priorities on its own, tends to lack funding, authority and business support.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan