A security program is the ongoing set of people, processes and technology that carries out governance. Managing it well means everyone knows who does what, people are trained for the risks they actually face, and leadership receives information it can act on.
Roles begin at the top. The board and executives own risk and set appetite. The chief information security officer (CISO) leads the program and advises leadership. Data owners (usually business leaders) decide how their data is classified and who may access it. Data custodians or system administrators implement the controls. Data stewards maintain data quality and definitions, and users follow policy. A privacy officer or data protection officer (DPO) handles privacy obligations where regulations require one.
A RACI matrix removes ambiguity for specific activities. For each task it names who is Responsible (does the work), Accountable (approves and answers for the outcome, only one per task), Consulted (gives input before) and Informed (told afterward). For example, for firewall rule changes the network team is Responsible, the network manager Accountable, security Consulted and the service desk Informed.
Awareness training should be role-based and continuous rather than a single yearly slideshow. Everyone needs basics such as phishing recognition and reporting; developers need secure coding; administrators need privileged account hygiene; executives need training on targeted fraud such as business email compromise. Phishing simulations are useful when they teach rather than shame, and the key measure is the reporting rate, not only the click rate.
Metrics turn the program into evidence. Key performance indicators (KPIs) measure how well a process runs, such as mean time to patch critical vulnerabilities. Key risk indicators (KRIs) warn that risk is rising, such as the number of internet-facing systems with known exploited vulnerabilities. Reports to leadership should be short, trend-based and tied to business impact and risk appetite, not a list of raw alert counts.
Key terms
- RACI matrix
- A chart assigning Responsible, Accountable, Consulted and Informed roles for each activity.
- Data owner
- The business leader accountable for a data set's classification and access decisions.
- Data custodian
- The person or team that implements and operates the controls protecting data.
- KPI
- Key performance indicator: a measure of how well a process is performing.
- KRI
- Key risk indicator: a measure that signals increasing exposure to a risk.
A CISO replaces a 40-page monthly report of alert counts with a one-page dashboard: patch SLA compliance for critical systems, phishing report rate, number of overdue risk exceptions and progress on the top five risks. The board can now see that exceptions are growing and asks business owners to close them.
Check yourself
Who decides how a customer database is classified: the database administrator or the head of sales?
The head of sales as the data owner; the DBA is a custodian who implements the controls.
Give one KPI and one KRI for vulnerability management.
KPI: percentage of critical vulnerabilities fixed within SLA. KRI: count of internet-facing assets with known exploited vulnerabilities open.