Governance should distinguish advice from approval
Security advising that something is risky is not the same as security refusing it.
Conflating them makes the security team a bottleneck and, more damagingly, makes them accountable for business decisions they do not own. Being clear about which conversations are advisory and which require an approval, and from whom, is what stops "security said no" becoming the explanation for everything.
More on Governance and risk
- 'compliance means secure'Certified, and propped open
- Risk is about uncertain impact, not merely bad thingsWhere it might land
- A risk register is a decision queue, not a museumNot a display case
- Risk acceptance spends organisational toleranceSigned, and spent
- Control effectiveness is separate from control existenceTicked, and still empty
- Risk owners need authority over the consequenceThe name, not the lever
