Summary
In this chapter, you have learned about the importance of assurance functions, that is, governance, risk, and compliance, and how their integration is key to effective and efficient information security management. You have also understood how organizations can use the maturity model to improve their processes. We discussed the importance of the commitment of senior management toward the security aspects of an organization.
Reading this chapter will have helped the CISM aspirant to get an overview of information security governance.
In our next topic, we will discuss the practical aspects of information security governance.