Security governance is the set of structures, responsibilities and processes through which senior leadership directs and controls security. The CISSP exam treats security as a business function, not a technical hobby. The right answer to a governance question is almost always the one that supports the organization's mission, goals and objectives, is sponsored by senior management and flows from the top down. A bottom-up approach, where the IT team decides security priorities on its own, tends to lack funding, authority and business support.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.