Cyber governance

Governance is deciding who decides, what is expected, and who carries the consequence. It is not the same as doing security.

Where it is absent, every decision becomes an argument settled by seniority or persistence, and nobody is accountable for the outcome either way. Where it is overdone, it becomes a committee that reviews documents. The useful version answers three questions: who owns this risk, what standard applies, and who may accept a departure from it.

Checked against the primary source.

More on Governance & risk