Topic 23 · Deep Dive

23.2 The Core Operational Pillars

Governance: Direction and Authority

Governance converts business intent into binding structure. It starts with a policy set written in tiers: an acceptable use policy and an information security policy signed by executives, supported by technical standards such as password rules, secure configuration baselines, and data classification requirements, then by procedures that name the actor, the trigger, and the record produced. Governance also owns the machinery of decision: a risk or security committee that reviews exceptions, approves changes to appetite, and assigns control ownership so that every requirement has a accountable human rather than a team. An exception register is the tell of real governance; if nobody can request a documented, expiring deviation, the policy is decoration.

Risk Management: Identify, Assess, Treat

The risk pillar runs a continuous loop. Identification inventories assets, data flows, threat sources, and known weaknesses, often seeded from architecture diagrams and vulnerability output. Assessment scores each scenario on likelihood and impact, sometimes using a five-by-five matrix, and the composite is compared against tolerance thresholds set by governance, which is what decides whether the CEO hears about it. Treatment selects a path: mitigate with a control, transfer through insurance or a contract, accept with a signed acknowledgement, or avoid by retiring the activity. The chosen treatment becomes a control with an owner and a due date, and the leftover exposure is residual risk carried in the register until the next review.

Compliance: Verification with Evidence

Compliance closes the loop from the outside in. Obligations are decomposed into testable requirements, each requirement is mapped to one or more controls, and each control needs evidence that is dated, attributable, and reproducible: a configuration export, an approval ticket, an access review sign-off. Validation happens through self-assessments, internal audits, and external auditors who sample a handful of instances and try to falsify the claim that the control operated throughout the period.

How the Pillars Interlock

Governance directs what risks may be carried, risk informs which obligations matter most, and compliance verifies whether the directions were followed, feeding findings back into both the register and the policy text. Break any arrow and the system degrades: policies with no risk input become unrealistic, risk with no verification becomes opinion.

Architecture Diagram

directs, informs, verifies Governance policies, steering, appetite Risk Management identify, assess, treat Compliance audit, validation, evidence directs informs verifies findings feed back
The pillars form a control loop: governance steers risk, risk scopes compliance, and audit findings rewrite both.

Key Takeaways

« Back to Topic 23« 23.1 / 23.3 »