Chapter 1: Information Security Governance
Governance is an important aspect of the certified information security manager (CISM) exam.
In this chapter, we will cover an overview of information security governance and aim to understand the impact of good governance on the effectiveness of information security projects.
You will learn about assurance functions such as governance, risk, and compliance (GRC), and details about the various roles and responsibilities of the security function. You will also be introduced to the best practices for obtaining the commitment from the senior management of an organization toward information security.
The following topics will be covered in this chapter:
- Introducing information security governance
- Understanding GRC
- Discovering the maturity model
- Getting to know the information security roles and responsibilities
- Finding out about the governance of third-party relationships
- Obtaining commitment from senior management
- Introducing the business case and the feasibility study
- Understanding information security governance metrics
Let's dive in and discuss each one of these topics in detail.