CYS403 Chapter 1
CYS403 · Chapter 1

Security Is a Business Decision:
Risk, Governance and Policy

Why every organization must treat cyber risk as a business priority, how governance frameworks connect IT value and IT risk, and how policy turns management intent into enforceable action.

Cyber RiskVal IT · Risk IT · COBITCIA TriadGovernancePolicy InfrastructureSecurity Planning
scroll ↓
01 / Why Care

Why Care About Cyber Risk?

Modern enterprises are dependent on automation and integration. Because systems are so connected, cyber risk cannot be managed inside a single IT silo: it has to cross IT silos and be integrated with the organization's existing levels of risk management.

The problem is a knowledge gap. According to a Nasdaq report, 91% of board members at the most vulnerable companies cannot interpret a cybersecurity report. That gap between executives and IT must be bridged:

Risk and value are two sides of the same coin

Risk is inherent to all enterprises. Enterprises earn their return by taking risks, so trying to eliminate every risk can remove the very risks that drive profit. Organizations must make sure that opportunities for value creation are not missed by trying to eliminate all risk. This is why guidance was needed on how to manage and capitalize on risk effectively.

Slide 5IT's business focus: business requirements drive IT resources and processes, which deliver the organisation's information (adapted from COBIT).

Common misconception

The aim of risk management is not zero risk. A business that avoids all risk also avoids its opportunities. The aim is to take the right risks and manage them to an acceptable level.

02 / Frameworks

IT Value, IT Risk and COBIT

Three ISACA frameworks work together to connect IT investment, IT risk, and IT governance:

Val IT
A governance framework used to create business value from IT investments.
Risk IT
Provides an end-to-end, comprehensive view of all risks related to the use of information technology.
COBIT
Gives management and business process owners an IT governance model that helps deliver value from IT and understand and manage the risks associated with IT.

Risk IT complements and extends COBIT and Val IT, making a more complete IT governance guidance resource.

Where IT risk fits in

Before Risk IT, available standards and frameworks were either too generic enterprise-risk-management-oriented or too IT-security-oriented. There was no comprehensive framework connecting the two, and Risk IT filled that gap.

Slide 10Risk IT, Val IT and COBIT overlap: risk management, value management and IT process management meet around IT-related events.
Slide 11Where IT risk fits in: existing frameworks were either generic enterprise-risk or IT-security oriented, leaving the gap Risk IT fills.

Memory trick · Which framework does what?

  • Val ITValue from IT investments
  • Risk ITRisk of using IT
  • COBITthe overall Control/governance model that covers both value and risk
03 / Principles

The Cybersecurity Triad and Business-Driven Security

Everything cybersecurity protects can be described by the three properties of the cybersecurity (CIA) triad:

Confidentiality
Information is disclosed only to those who are authorized to see it.
Integrity
Information and systems are accurate, complete, and protected from unauthorized modification.
Availability
Information and systems are accessible to authorized users when they are needed.

Business-driven security

Business-driven security means creating a security strategy that aligns with the business's needs. Security exists to support the organization, not the other way round.

Organizational and business requirements

Complete security solutions

Functional requirements

Define the security behavior of the control measure. They are selected based on the risk management process.

Assurance requirements

Provide confidence that the security function is performing as expected. Assurance is a critical part of the security program.

Slide 13The business-driven security lifecycle: a security strategy that aligns with business needs.
Slide 14IT security requirements structure: corporate governance at the top, security solutions at the base.

Functional vs assurance

Functional = what the control does. Assurance = proof that it actually does it. A firewall rule is functional; an audit showing the rule works is assurance.

04 / Management

Cybersecurity Management and Governance

Cybersecurity management is everything an organization does to protect its information systems and computer networks from cyber attacks, intrusions, malware, and various types of data breaches.

Cybersecurity Management
Governance
Risk Management

Cybersecurity management includes two parts: governance and risk management.

Cybersecurity governance

Governance

Sets direction and oversight: what the organization should achieve, and holds management accountable for it.

Management

Plans and executes the activities that achieve that direction day to day.

Security blueprints

Security blueprints provide a structure for organizing requirements and solutions, ensure that security is considered holistically, and are used to identify and design security requirements.

Slide 17Cybersecurity management spans people, process and technology.
Slide 18Strategic policies and frameworks feed the tactical guidelines, baselines and procedures.
Slide 19Governance (evaluate, direct, monitor) versus management (plan, build, run, monitor).
Slide 20Where the CISO and CRO sit in the organisation chart.
05 / Policy

The Policy Environment and Policy Infrastructure

At the top of the policy hierarchy is the overarching organizational policy, also called management's security statement. It does not exist in a vacuum: it is shaped by the environment around it.

Environmental influence Why it shapes policy
Laws Legal obligations the organization must obey.
Regulations Industry or government rules (e.g. data protection).
Organizational goals Long-term aims the policy must support.
Organizational objectives Specific, measurable targets.
Shareholders' interests Owners expect assets and reputation to be protected.

Policy infrastructure

1

High-level policies are interpreted into functional policies

The overarching statement is too broad to act on, so it is broken down into topic-specific functional policies.

2

Functional policies create the foundation

Derived from the overarching policy, they are the foundation for procedures, standards, and baselines that accomplish the objectives.

3

Policies gain credibility through top management buy-in

Without visible executive support, policies are ignored.

Examples of functional policies

# Functional policy
1 Data classification
2 Certification and accreditation
3 Access control
4 Outsourcing
5 Remote access
6 Acceptable mail and Internet usage
7 Privacy
8 Dissemination control
9 Sharing control
Slide 23The policy environment: regulations, laws, goals, objectives and shareholder interests shape the overarching policy.
Slide 24Policy hierarchy: the overarching policy drives functional policies, carried out through standards, baselines, procedures and guidelines.

Example

An Internet usage policy is a functional policy: it applies the security statement to one topic (how employees may use the Internet) and is then enforced through standards and procedures.

06 / Implementation

Standards, Procedures, Guidelines and Baselines

Standards, procedures, baselines, and guidelines turn management objectives and goals (functional policies) into enforceable actions for employees.

Security statement
Functional policies
Standards · Procedures · Baselines · Guidelines
Element Definition Examples
Standards (local) Adoption of common hardware and software mechanisms and products throughout the enterprise. Desktop, anti-virus, firewall
Procedures Step-by-step actions that must be followed to accomplish a task. How to create a user account
Guidelines Recommendations for product implementations, procurement, and planning. ISO 17799, Common Criteria, ITIL
Baselines Benchmarks that ensure a minimum level of security configuration across implementations and systems; establish consistent implementation; platform unique. VPN setup, IDS configuration, password rules
Slide 26The four supporting documents: standards, procedures, baselines and guidelines.

Memory trick · Tell them apart

  • StandardsWHAT product
  • ProceduresHOW, step by step
  • GuidelinesSHOULD (recommended)
  • BaselinesMINIMUM configuration

Only guidelines are optional recommendations.

Classic trap

ISO 17799, Common Criteria, and ITIL are listed on the slides as examples of guidelines, not standards. Password rules and IDS configuration are baselines.

07 / Planning

Three Levels of Security Planning

Level Time frame Focus Example
Strategic Long term High-level, long-range organizational requirements Overall security policy
Tactical Medium term Events that affect the whole organization Functional plans
Operational Short term Very specific actions reacting to an incident (fighting fires at the keyboard level); directly affects how objectives are accomplished Responding to a specific incident
Strategic (long)
Tactical (medium)
Operational (short)

Memory trick · S-T-O

StrategyTacticsOperations

from the boardroom's long view, to organization-wide plans, down to the keyboard-level response.

08 / Big Idea

Security Transcends Technology

The chapter closes with its key message: security transcends technology. Firewalls and anti-virus are not enough on their own; security depends on business alignment, governance, policy, people, and above all risk management, which the rest of the course builds on.

Slide 33Governance, risk and compliance as one continuous cycle.

Link to the next chapters

Chapter 2 defines risk precisely, Chapter 3 studies threats and vulnerabilities, and Chapters 4–6 turn them into a full risk assessment.

09 / Exam Prep

Exam Tips & Tricks

91% statistic

91% of board members at the most vulnerable companies cannot interpret a cybersecurity report (Nasdaq). It shows the executive–IT knowledge gap.

Risk and value

Risk and value are two sides of the same coin. Don't eliminate all risk: you would also eliminate value creation.

V-R-C frameworks

Val IT = value from IT investments; Risk IT = end-to-end view of IT risk; COBIT = IT governance model. Risk IT complements and extends COBIT and Val IT.

Management = governance + RM

Cybersecurity management includes governance and risk management. Governance is an integral part of corporate governance.

Functional vs assurance

Functional requirements define security behavior (chosen by risk management); assurance requirements give confidence it works.

Policy order

Security statement → functional policies → standards, procedures, baselines, guidelines. Policies gain credibility through top management buy-in.

Guidelines vs baselines

Guidelines are recommendations (ISO 17799, Common Criteria, ITIL). Baselines are minimum configurations (VPN setup, IDS config, password rules).

Planning levels

Strategic = long term (security policy); tactical = medium term (functional plans); operational = short term, keyboard-level incident response.

10 / Self-Test

Flashcards — Test Yourself

Say the answer out loud, then flip the card to check. Shuffle the deck to test yourself in a new order.

11 / Cheat Sheet

Quick Reference — Everything at a Glance

Topic Key Point
Why care about cyber risk Enterprises depend on automation/integration; risk must cross IT silos and integrate with existing risk management.
Board knowledge gap 91% of board members at the most vulnerable companies can't interpret a cybersecurity report.
Risk vs value Two sides of the same coin; enterprises achieve return by taking risks.
Val IT Governance framework to create business value from IT investments.
Risk IT End-to-end, comprehensive view of all IT-related risks; extends COBIT and Val IT.
COBIT IT governance model for delivering value from IT and managing IT risks.
CIA triad Confidentiality, integrity, availability.
Business-driven security Security strategy aligned with business needs; mission-focused and cost effective.
Functional requirements Define security behavior of a control; selected by risk management.
Assurance requirements Confidence that the security function performs as expected.
Cybersecurity management Protecting systems and networks from attacks, intrusions, malware, breaches; includes governance + risk management.
Cybersecurity governance Part of corporate governance; IT meets requirements, supports strategy, includes SLAs if outsourced.
Security blueprints Structure for organizing requirements and solutions; holistic security design.
Overarching policy Management's security statement; shaped by laws, regulations, goals, objectives, shareholders.
Functional policies Data classification, C&A, access control, outsourcing, remote access, mail/Internet use, privacy, dissemination, sharing.
Standards / procedures Common mechanisms and products / step-by-step actions.
Guidelines / baselines Recommendations (ISO 17799, CC, ITIL) / minimum security configuration (VPN, IDS, passwords).
Planning levels Strategic (long), tactical (medium), operational (short).