Security Notes
Governance, Risk & Compliance

Security Governance, Risk & Assurance

The managerial side of security: how an organisation decides what to protect, how much risk it accepts, who is accountable, how it tests that controls work, and how it runs security day to day. This is the core of CISSP domains 1, 2, 6 and 7, and it is what senior and staff-level interviews probe when they ask "how would you prioritise?" or "how do you justify that spend?"

18 min read 7 sections 8 model answers

Ethics, Accountability and the Governance Document Stack

What is this?

Governance is the system of decisions and accountability that sits above the technical controls: who decides, what the rules are, and who answers when they are broken. Ethics is the set of principles security professionals are held to when no rule covers the situation.

Why it matters

Technical controls without governance drift: nobody owns them, nobody funds them, and nobody can say whether they are enough. In interviews, governance questions test whether you can talk to executives and auditors, not just engineers.

How it works

The ISC2 Code of Ethics

Four canons, in priority order. When they conflict, the higher one wins:

  1. Protect society, the common good, necessary public trust and confidence, and the infrastructure.
  2. Act honourably, honestly, justly, responsibly and legally.
  3. Provide diligent and competent service to principals.
  4. Advance and protect the profession.

Example: your employer (canon 3) asks you to hide a breach that exposes customers' data. Canon 1 and 2 outrank canon 3, so you escalate and refuse.

Due care versus due diligence

Due diligence

finding out: researching, assessing and understanding the risks before and during an activity (vendor assessments, risk assessments, audits).

Due care

acting on it: doing what a reasonable person would do to protect assets (patching, enforcing policy, training).

Memory aid: diligence is thinking, care is doing. Failure of due care is the basis of negligence.

The document stack

Policy        WHAT and WHY. Mandatory, high-level, approved by senior management.
  │           "All customer data must be encrypted at rest."
  ▼
Standard      Mandatory specifics that make the policy measurable.
  │           "AES-256 via the cloud KMS; keys rotated annually."
  ▼
Baseline      Mandatory minimum configuration for a system type.
  │           "CIS Level 1 benchmark for all Linux servers."
  ▼
Procedure     Mandatory step-by-step HOW.
  │           "To enable encryption on a new database, do 1… 2… 3…"
  ▼
Guideline     RECOMMENDED advice, not mandatory.
              "Prefer client-side encryption for regulated data sets."

Roles

Senior management

ultimately accountable for security; approves policy and accepts risk.

CISO (chief information security officer)

runs the security programme and advises management.

Data owner

a business leader accountable for a data set; decides its classification and who may access it.

Data custodian

implements the owner's decisions day to day (IT, cloud platform teams).

Data steward

responsible for data quality and correct use.

Data controller and processor

(privacy law terms) — the controller decides why and how personal data is processed; the processor processes it on the controller's behalf. A SaaS vendor is usually the processor.

Users

follow policy.

Security frameworks and control types

Control categories

administrative (policy, training), technical/logical (encryption, firewalls) and physical (locks, guards).

Control functions

preventive, detective, corrective, deterrent, recovery, compensating (an alternative control when the primary one is impractical) and directive.

Frameworks such as NIST CSF, ISO 27001 and SOC 2 are compared in compliance frameworks.

📰

Real incident — the Uber breach cover-up (2016–2022). Attackers stole data on 57 million Uber riders and drivers and demanded payment. Uber's chief security officer had the payment made through the bug-bounty programme, with the attackers signing non-disclosure agreements, and the breach wasn't disclosed to regulators for a year. In 2022 he was convicted of obstruction and concealing a felony. The canons' order is not academic: concealment to protect the employer put a security leader on trial.

🎯

On the job. Governance shows up as a question you should ask whenever you're told to accept something: "who is accepting this risk, and is it written down?" A risk accepted by an engineer in a Slack thread hasn't been accepted.

Security angle

The most common governance failure is responsibility without authority: a security team "owns" a risk it has no power to fix. Make the data owner and senior management accountable for accepting risk, in writing.


Risk Management

What is this?

Risk is the chance that a threat (something that can cause harm) exploits a vulnerability (a weakness) and damages an asset (something of value). Risk management is the cycle of finding risks, sizing them, choosing what to do about each, and watching for change.

Why it matters

Security budgets are always smaller than the list of risks. Risk management is how you choose, and how you explain the choice to someone who controls the budget.

How it works

Quantitative risk analysis — putting numbers on it

TermMeaningExample
AV — asset valueWhat the asset is worthCustomer database: $2,000,000
EF — exposure factorShare of value lost in one incidentA breach costs 30% → 0.3
SLE — single loss expectancyAV × EF$2,000,000 × 0.3 = $600,000
ARO — annualised rate of occurrenceExpected incidents per yearOnce every 4 years → 0.25
ALE — annualised loss expectancySLE × ARO$600,000 × 0.25 = $150,000 per year

A control is worth buying when it lowers the ALE by more than it costs per year:

Value of control = ALE before − ALE after − annual cost of control
                 = $150,000 − $30,000 − $50,000 = $70,000  → worth it

Qualitative risk analysis

When numbers are guesses, rate likelihood and impact on a scale (low, medium, high) and plot them on a heat map. Faster and easier to agree on, less precise. Most real programmes use qualitative analysis and quantify only the biggest decisions.

Risk responses

Mitigate (reduce)

add controls to lower likelihood or impact.

Transfer (share)

move the financial impact to someone else: cyber insurance, outsourcing with contractual liability.

Avoid

stop the activity that creates the risk (don't store card numbers at all).

Accept

knowingly live with it, signed off by someone with authority, and reviewed periodically.

Ignoring

a risk is not acceptance; it is a governance failure.

Inherent risk is risk before controls; residual risk is what remains after them. Residual risk must sit within the organisation's risk appetite (how much risk it is willing to take in pursuit of its goals); anything above it needs more treatment or an explicit acceptance.

Frameworks

NIST SP 800-37 (Risk Management Framework: categorise, select, implement, assess, authorise, monitor), NIST SP 800-30 (how to conduct a risk assessment), ISO 31000 and ISO/IEC 27005. Threat modelling methods such as STRIDE feed the "threat" side; see threat modelling.

Supply-chain risk management

Your risk includes your suppliers' risk. Assess vendors before onboarding (questionnaires, SOC 2 reports, ISO certificates), set security requirements in contracts (breach notification times, right to audit), track a software bill of materials, and reassess regularly. See dependency management for the software side.

Security awareness

Training changes behaviour only if it is targeted and repeated: role-based training (developers, finance staff targeted by payment fraud), phishing simulations with coaching rather than punishment, and metrics such as report rate, not just click rate.

In practiceA risk register line, the artefact executives actually read:

IDRiskLikelihoodImpactInherentControlsResidualOwnerDecisionReview
R-17Ransomware encrypts file servers and backupsMediumSevereHighEDR, immutable off-site backups, MFA on adminMediumCOOMitigate: segment backups by Q12027-01
R-22Legacy payroll app can't support SSOHighModerateMediumIP allow-list, quarterly access reviewMediumCFOAccept until replacement (signed 2026-09-14)2027-03
📰

Real incident — Equifax (2017). A critical Apache Struts vulnerability (CVE-2017-5638) was publicly disclosed and patched in March 2017. Equifax's internal alert went out, but one internet-facing dispute portal wasn't patched. Attackers got in two months later and stole data on about 147 million people over 76 days, unseen partly because an expired certificate on a traffic-inspection device had silently stopped it working. Every control existed on paper; ownership and verification didn't.

🎯

On the job. When presenting a risk, give the decision-maker options with costs: "mitigate for £X by date Y, transfer partly through insurance, or accept with this residual" — and record which they chose.

Security angle

Quantitative numbers look precise but are built on estimates; present ranges and say what drives them. And watch for "accepted" risks that were never formally accepted, which is a common audit finding.


Asset Security — Classification, Handling and Disposal

What is this?

Knowing what information you have, how sensitive it is, who owns it, how it must be handled through its life, and how to destroy it when it is no longer needed.

Why it matters

You cannot protect what you have not found or labelled. Many breaches involve data that should have been deleted years earlier.

How it works

Classification

Government/military style

Top Secret, Secret, Confidential, Unclassified.

Commercial style

Confidential (or Restricted), Private, Sensitive, Public.

Classification is set by the data owner, based on the impact of disclosure, and drives handling rules: encryption, who may access it, where it may be stored, and retention.

Data states

At rest

stored on disk or in a database; protect with encryption and access control.

In transit

moving over a network; protect with TLS, IPsec or VPN.

In use

being processed in memory; the hardest to protect. Confidential computing (hardware-isolated enclaves) addresses this.

Data lifecycle

Create/collect → Store → Use → Share → Archive → Destroy

At each stage ask: who can access it, is it encrypted, is it logged, and does a retention rule say it should already be gone?

Data remanence and sanitisation

Remanence is data left behind after a "delete." NIST SP 800-88 defines three levels of sanitisation:

Clear

overwrite with logical techniques so ordinary tools can't recover the data. Fine for reuse inside the organisation.

Purge

make recovery infeasible even with laboratory techniques: cryptographic erase, block erase on SSDs, degaussing for magnetic media.

Destroy

physically shred, disintegrate, pulverise or incinerate. The only option for failed drives you can't erase.

SSDs need special care: wear-levelling means overwriting a file does not overwrite every copy, so use the drive's sanitise command or cryptographic erase. In the cloud, crypto-shredding (deleting the encryption key) is the practical purge.

Baselines, scoping and tailoring

Start with a standard control baseline (NIST SP 800-53, CIS Benchmarks). Scoping removes controls that don't apply (no wireless controls on a system without wireless). Tailoring adjusts the remaining controls to the organisation (stricter password length, compensating controls).

Data loss prevention (DLP)

DLP tools inspect data at endpoints, on the network and in cloud services, find sensitive patterns (card numbers, national IDs, labelled documents) and block, quarantine or alert when they leave approved locations. DLP depends on good classification and creates false positives, so start in monitor mode.

📰

Real incident — Morgan Stanley's discarded hardware (fined 2022). Morgan Stanley hired a moving company with no data-destruction experience to decommission data-centre hardware. Devices containing unencrypted customer data were resold and turned up on an internet auction site; the firm recovered only some of them. The US SEC fined it $35 million, after an earlier $60 million penalty from the US banking regulator over the same programme. Disposal is a security control, and so is overseeing the vendor who performs it.

🎯

On the job. Ask for the certificate of destruction (with serial numbers) from disposal vendors, encrypt every drive so loss becomes a non-event, and make sure decommissioning in the cloud includes snapshots, backups and replicas, not just the instance.

Security angle

Keep less data. Data you don't hold can't be breached, subpoenaed or ransomed.


Security Assessment and Testing

What is this?

The ways an organisation checks that its controls actually work: scanning, penetration testing, audits, code review and ongoing measurement.

Why it matters

Controls decay. An untested control is an assumption. Interviewers ask you to distinguish these assessment types and to say which fits a given goal.

How it works

  • Vulnerability assessment — automated scanning plus analysis to list known weaknesses. Broad, frequent, does not exploit.
  • Penetration test — authorised humans exploit weaknesses to show real impact. Narrower and deeper. Needs written authorisation and rules of engagement: scope, timing, allowed techniques, contacts, and how to handle sensitive data found.
    Black box

    no prior knowledge (simulates an outsider).

    Grey box

    partial knowledge, such as a user account.

    White box

    full knowledge, including source code and architecture.

  • Red team — an objective-driven, stealthy simulation of a real adversary that tests detection and response, not just prevention. Purple teaming has attackers and defenders work together to improve detections. Breach and attack simulation tools run automated attack techniques continuously.
  • Audits
    Internal (first party)

    by the organisation's own audit team.

    External (second party)

    by a customer auditing a supplier.

    Third party

    by an independent body, such as a SOC 2 auditor or ISO certification body.

  • Code review and testing — static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), manual review, and fuzzing (feeding malformed input to find crashes). See SAST, DAST and SCA.
  • Synthetic transactions — scripted transactions run continuously against production to verify availability and behaviour; real user monitoring observes actual users.
  • Misuse case testing — testing what a system should not allow, written from an attacker's point of view.
  • Log reviews and account reviews — periodic checks that logs are collected and reviewed and that access is still appropriate.
  • Metrics
    KPIs (key performance indicators)

    how well the security programme is performing: mean time to detect, patch coverage, phishing report rate.

    KRIs (key risk indicators)

    early warnings that risk is rising: number of critical vulnerabilities older than 30 days, privileged accounts without MFA.

In practiceThe rules of engagement fit on one page, and every line prevents a real failure:

Scope:        acme.com, *.acme.com, 203.0.113.0/24, office at 1 High St (physical: lobby + floor 2 only)
Out of scope: payments processor, third-party SaaS, denial-of-service, social engineering of the CEO
Window:       2026-11-03 to 2026-11-14, 08:00–20:00 UTC; production writes require approval
Authorised by: CISO (signature) AND building owner (signature) for physical testing
Emergency stop: +44 … (24/7), testers carry a signed authorisation letter
Data handling: no exfiltration of real customer data; screenshots redacted; findings encrypted
📰

Real incident — the Iowa courthouse arrests (2019). Two penetration testers hired by the state judicial branch were arrested while testing physical security at a county courthouse at night. The state had authorised the test, but the county owned the building and hadn't agreed. The charges were eventually dropped, but the case changed how the industry writes scope: everyone who owns what you're testing must sign.

🎯

On the job. Read a pentest report for what it didn't test as much as what it found: scope exclusions, time limits and "not exploited due to rules of engagement" items are where real attackers will go.

Security angle

A clean penetration test proves only that those testers found nothing in that scope in that week. Pair point-in-time tests with continuous scanning, detection testing and attack simulation.


Operational Governance — Change, Configuration and Patch Management

What is this?

The routine processes that stop well-meaning changes from creating vulnerabilities or outages.

Why it matters

A large share of outages and many exposures come from changes: a firewall rule opened "temporarily," an unpatched server, a configuration that drifted from the baseline.

How it works

Change management

every change is requested, assessed for risk, approved (by a change advisory board for significant changes), tested, scheduled, implemented with a rollback plan, and documented. Emergency changes are allowed but reviewed afterwards.

Configuration management

keep an inventory of assets and their approved baseline configuration (often in a configuration management database), detect drift, and restore the baseline.

Patch management

inventory → identify available patches → prioritise by severity and exposure (an internet-facing critical vulnerability with a public exploit first) → test → deploy → verify. Track exceptions with compensating controls.

Separation of duties and job rotation

no single person can make and approve a change; rotation exposes fraud that depends on one person staying in post. Mandatory vacations serve the same purpose.

Least privilege and need to know

access only to what the job needs, reviewed regularly.

In practiceInfrastructure as code turns a change request into a reviewable diff:

diff
 resource "aws_security_group_rule" "admin_ssh" {
   type        = "ingress"
   from_port   = 22
   to_port     = 22
-  cidr_blocks = ["10.0.0.0/8"]
+  cidr_blocks = ["0.0.0.0/0"]        # "temporary, for the vendor"   ← reviewer should block this
 }
📰

Real incident — CrowdStrike content update (2024). A configuration update to a security agent with kernel access was pushed to customers worldwide at once and crashed about 8.5 million Windows machines. CrowdStrike's own review pointed to testing gaps and the lack of staged rollout for that type of content. Change management applies to "just configuration" and to security tools too: test, canary, stage, and keep a rollback.

🎯

On the job. Measure patching by exposure, not by count: time to patch internet-facing critical vulnerabilities with a known exploit (the CISA KEV list) is the number that matters.

Security angle

Infrastructure as code turns change management into code review: the pull request is the change request, the pipeline is the implementation, and git history is the audit trail.


Investigations and Evidence

What is this?

The kinds of investigations a security team may support and the rules evidence must meet to be usable.

Why it matters

The standard of proof and the handling rules differ by investigation type. Mishandled evidence can make a criminal case collapse or an employment decision unlawful.

How it works

Administrative

internal policy violations; lowest standard, handled by the organisation.

Criminal

violations of criminal law; law enforcement leads; proof beyond a reasonable doubt.

Civil

disputes between parties; proof on the preponderance of the evidence (more likely than not).

Regulatory

by or for a regulator; standard depends on the regulation.

Admissible evidence must be relevant, reliable (collected properly, chain of custody intact) and lawfully obtained. Evidence types include real (physical objects), documentary, testimonial and demonstrative. Chain of custody records who handled evidence, when and why, from collection to court. See digital forensics for acquisition and writing reports.

Personnel safety always comes first: duress codes, travel security, and evacuation procedures outrank asset protection. On the exam, the answer that protects people wins.

In practiceA chain-of-custody record is a simple table that must never have gaps:

ItemDescriptionSHA-256Collected byDate/time (UTC)Transferred toPurpose
E-01Laptop SN 5CG2341, user jdoen/a (physical)A. Patel2026-10-02 14:12Evidence locker #3Preserve
E-02Disk image of E-019b1f…c04eA. Patel2026-10-02 16:40Forensics share (read-only)Analysis
🎯

On the job. Assume any serious incident could end up in court or an employment tribunal: hash evidence on collection, work on copies, log every handler, and keep analysts' notes timestamped.

Security angle

Decide early whether an incident might become a legal matter; if so, involve legal counsel, preserve evidence forensically and avoid tipping off the subject. See analyst OPSEC.


Interview Questions

Q
Explain due care versus due diligence with an example.
Model answer

Due diligence is finding out — assessing a vendor's security before signing, or running a risk assessment. Due care is acting on what you learned — requiring the vendor to fix gaps, patching, enforcing policy — the way a reasonable organisation would. If you knew about a risk and didn't act, you failed due care, and that's what negligence claims are built on.

Q
Walk me through a quantitative risk calculation.
Model answer

Single loss expectancy is asset value times exposure factor, so a two-million-dollar database losing 30% per breach is a 600 thousand dollar SLE. Multiply by the annual rate of occurrence — say once every four years, 0.25 — and you get an annualised loss expectancy of 150 thousand a year. A control is worth it if it cuts that ALE by more than it costs annually, and I'd always present the inputs as ranges because they're estimates.

Q
What are the four ways to respond to a risk?
Model answer

Mitigate it with controls, transfer it through insurance or contracts, avoid it by stopping the activity, or accept it knowingly. Acceptance must be a signed decision by someone with authority, usually the data owner or senior management, and revisited periodically. Ignoring a risk isn't acceptance — it's a governance gap, and auditors treat it that way.

Q
What's the difference between a policy, a standard, a procedure and a guideline?
Model answer

A policy states what must happen and why, at a high level, approved by leadership — for example, customer data must be encrypted. A standard makes it measurable, like AES-256 with yearly key rotation; a procedure is the step-by-step how; and a guideline is recommended but optional advice. Policies, standards, baselines and procedures are mandatory; guidelines aren't.

Q
How do you securely dispose of SSDs and cloud data?
Model answer

For SSDs, overwriting isn't reliable because of wear-levelling, so I'd use the drive's built-in sanitise or cryptographic erase command, which NIST 800-88 counts as purge, and physically destroy any drive that can't be erased. In the cloud you can't touch the media, so the practical purge is crypto-shredding: encrypt everything under keys you control and delete the keys. Then record a certificate of sanitisation for the audit trail.

Q
What's the difference between a vulnerability assessment, a penetration test and a red team?
Model answer

A vulnerability assessment lists known weaknesses broadly and often, without exploiting them. A penetration test has authorised people exploit weaknesses within an agreed scope to prove impact. A red team is objective-driven and stealthy, emulating a real adversary to test whether detection and response work, not just prevention. They answer different questions, so a mature programme uses all three.

Q
What's the difference between a KPI and a KRI?
Model answer

A key performance indicator measures how well the security programme is running, like mean time to detect or patch coverage. A key risk indicator is an early warning that risk is rising, like the number of internet-facing critical vulnerabilities older than 30 days. Executives need both: one shows the team is effective, the other shows where exposure is growing.

Q
An executive asks you to quietly delete logs showing a data exposure. What do you do?
Model answer

I refuse and escalate. The ISC2 code puts protecting society and acting honestly and legally above service to an employer, and destroying evidence of a breach could also break notification laws and be obstruction. I'd preserve the logs, document the request, and take it to legal counsel or the appropriate oversight function.