The Importance of Program Governance
First, let’s take a high-level look at all sub-functions that should be addressed as part of the governance function. The following image captures much of what the governance function entails.
Figure 13.1: Sub-functions of the governance function
Although GRC are considered a unified program, we will be covering them separately because each serves its own unique purpose as it relates to the broader cybersecurity program, as described below:
- Governance: Governance is the overarching component of your cybersecurity program. This is the program that ensures alignment with the organization’s objectives in addition to any compliance or regulation requirements. This is where you bridge the gap between the cybersecurity program and your executive leadership team, including the board of directors (if applicable), to ensure that full transparency and accountability sit at the correct level of the organization. This...