23.2 The Core Operational Pillars
Governance: Direction and Authority
Governance converts business intent into binding structure. It starts with a policy set written in tiers: an acceptable use policy and an information security policy signed by executives, supported by technical standards such as password rules, secure configuration baselines, and data classification requirements, then by procedures that name the actor, the trigger, and the record produced. Governance also owns the machinery of decision: a risk or security committee that reviews exceptions, approves changes to appetite, and assigns control ownership so that every requirement has a accountable human rather than a team. An exception register is the tell of real governance; if nobody can request a documented, expiring deviation, the policy is decoration.
Risk Management: Identify, Assess, Treat
The risk pillar runs a continuous loop. Identification inventories assets, data flows, threat sources, and known weaknesses, often seeded from architecture diagrams and vulnerability output. Assessment scores each scenario on likelihood and impact, sometimes using a five-by-five matrix, and the composite is compared against tolerance thresholds set by governance, which is what decides whether the CEO hears about it. Treatment selects a path: mitigate with a control, transfer through insurance or a contract, accept with a signed acknowledgement, or avoid by retiring the activity. The chosen treatment becomes a control with an owner and a due date, and the leftover exposure is residual risk carried in the register until the next review.
Compliance: Verification with Evidence
Compliance closes the loop from the outside in. Obligations are decomposed into testable requirements, each requirement is mapped to one or more controls, and each control needs evidence that is dated, attributable, and reproducible: a configuration export, an approval ticket, an access review sign-off. Validation happens through self-assessments, internal audits, and external auditors who sample a handful of instances and try to falsify the claim that the control operated throughout the period.
How the Pillars Interlock
Governance directs what risks may be carried, risk informs which obligations matter most, and compliance verifies whether the directions were followed, feeding findings back into both the register and the policy text. Break any arrow and the system degrades: policies with no risk input become unrealistic, risk with no verification becomes opinion.
Architecture Diagram
Key Takeaways
- Governance is tiered: signed policy, standards, procedures, plus a committee and an expiring exception register.
- Risk management is a loop of identify, assess, treat, with tolerance thresholds deciding escalation.
- Treatment options are mitigate, transfer, accept, or avoid; the leftover exposure is residual risk with an owner.
- Compliance needs dated, attributable, reproducible evidence, because auditors test samples rather than intentions.
- The pillars interlock as directs, informs, verifies; a break in any arrow collapses the whole loop.