After completing this tutorial, you should be able to:
Welcome to Unit 6: Management Issues with Computer and Network Security. This unit marks a critical transition in COMP400: after building a strong technical foundation in cryptography, network security, access control, and system hardening, we now turn to the human, organizational, and managerial dimensions that determine whether security controls actually protect an enterprise.
Tutorial 6.1 establishes the conceptual bedrock for the entire unit. We explore the relationship between security management and information security governance—two terms that are often conflated but serve distinct purposes. Governance establishes the direction, accountability, and oversight for security, while management implements the plans, processes, and controls that execute that direction. Together, they form the spine of an enterprise security program.
Why does this matter? Consider a large financial institution that deploys state-of-the-art firewalls, intrusion detection systems, and endpoint protection, yet suffers a devastating data breach because no one was accountable for patching a critical vulnerability, or because the security team operated in a silo without executive support. Technical controls alone are insufficient; they must be embedded within a governance framework that ensures strategy, resources, and culture align to protect the organization's most valuable assets.
In this tutorial, we will examine:
This tutorial sets the stage for the rest of Unit 6. Subsequent tutorials will delve into risk assessment (6.3, 6.4), policy development (6.5), security controls (6.6), incident response (6.8), business continuity (6.9), physical security (6.10), human factors (6.12–6.14), auditing (6.15), and legal/ethical issues (6.17, 6.18). By the end of this unit, you will understand not only how to secure systems, but why organizations succeed or fail at security—and how you can influence that outcome as a security professional.
Information security management is the systematic process of identifying an organization's information assets, assessing the risks to those assets, and implementing appropriate controls to protect their confidentiality, integrity, and availability (the CIA triad). It encompasses the policies, procedures, organizational structures, and technologies that collectively safeguard information resources.
At its core, security management is a business function, not merely a technical one. Effective security managers must understand the organization's mission, risk appetite, regulatory obligations, and operational constraints. They translate these business requirements into security strategies that are both effective and cost-efficient.
One of the most important concepts in security leadership is the distinction between governance and management. Though often used interchangeably in casual conversation, they serve fundamentally different functions.
| Aspect | Governance | Management |
|---|---|---|
| Primary focus | Direction, oversight, and accountability | Execution, operations, and implementation |
| Key question | "Are we doing the right things?" | "Are we doing things right?" |
| Responsible parties | Board of directors, executive leadership, security steering committee | Chief Information Security Officer (CISO), security managers, security analysts |
| Time horizon | Strategic (1–5+ years) | Tactical / operational (days to months) |
| Key outputs | Policies, risk appetite statements, strategic plans, compliance mandates | Procedures, controls, budgets, training programs, incident response |
| Accountability | Fiduciary and legal responsibility to stakeholders | Operational responsibility to achieve security objectives |
In practice, governance sets the rules of the game, while management plays the game. Governance ensures that security aligns with organizational strategy, that risks are understood at the highest levels, and that resources are allocated appropriately. Management translates governance directives into concrete actions, monitors their effectiveness, and reports back to governance bodies.
A security program is the set of integrated activities, processes, and controls that an organization uses to manage information security. Like any management discipline, security programs follow a lifecycle of continuous improvement.
The Plan-Do-Check-Act (PDCA) cycle, adapted from quality management, provides a useful model:
This lifecycle is not a one-time project; it is a continuous loop that reflects the dynamic nature of cybersecurity. Threats evolve, technology changes, and business requirements shift. A mature security program embraces this cycle and institutionalizes processes for ongoing adaptation.
┌─────────────────────────────────────────────────┐
│ SECURITY PROGRAM LIFECYCLE │
│ (PDCA Model) │
└─────────────────────────────────────────────────┘
┌──────────────┐
│ PLAN │
│ Strategy & │
│ Design │
└──────┬───────┘
│
▼
┌──────────────┐
│ DO │
│ Implement │
│ Controls │
└──────┬───────┘
│
▼
┌──────────────┐
│ CHECK │
│ Monitor & │
│ Evaluate │
└──────┬───────┘
│
▼
┌──────────────┐
│ ACT │
│ Correct & │
│ Improve │
└──────────────┘
│
└──────────► (return to PLAN)
Information security governance (or cybersecurity governance) is the set of structures, processes, and practices that provide strategic direction for security, ensure that security objectives are achieved, and verify that risks are managed appropriately. It is the oversight function that ensures security activities are aligned with business goals and that there is accountability for security outcomes.
The Five Principles of Security Governance, as articulated by the Information Security Forum (ISF) and adapted by NIST, include:
Cybersecurity governance has become a board-level priority in the wake of high-profile breaches, regulatory fines, and growing public awareness of data privacy. Consider these driving factors:
Effective governance transforms security from a "cost centre" into a strategic enabler that supports innovation, competitive advantage, and long-term resilience.
Governance is not a single role or department; it is a system of layers that cascades accountability from the board of directors down to operational teams. The following pyramid illustrates a typical governance structure in a large enterprise.
┌─────────────────────────────────────────────────────────────┐
│ BOARD OF DIRECTORS │
│ Ultimate fiduciary responsibility │
│ Approves risk appetite, oversees strategy │
└──────────────────────────┬──────────────────────────────────┘
│
┌──────────────────────────▼──────────────────────────────────┐
│ EXECUTIVE LEADERSHIP (CEO, CFO, etc.) │
│ Sets enterprise strategy & risk posture │
│ Allocates resources; appoints CISO │
└──────────────────────────┬──────────────────────────────────┘
│
┌──────────────────────────▼──────────────────────────────────┐
│ SECURITY STEERING COMMITTEE (SSC) │
│ Cross-functional leadership (IT, legal, risk, ops) │
│ Reviews security program, approves major changes │
│ Escalates to executive team │
└──────────────────────────┬──────────────────────────────────┘
│
┌──────────────────────────▼──────────────────────────────────┐
│ CHIEF INFORMATION SECURITY OFFICER (CISO) │
│ Owns the security program; manages security team │
│ Reports to CIO, CEO, or board as appropriate │
└──────────────────────────┬──────────────────────────────────┘
│
┌──────────────────────────▼──────────────────────────────────┐
│ SECURITY MANAGEMENT & OPERATIONS │
│ Security architects, engineers, analysts, auditors │
│ Implement controls, monitor threats, respond to events │
└─────────────────────────────────────────────────────────────┘
A common pitfall in security management is treating security as a technical add-on rather than an integral business function. When security is disconnected from business strategy, it can become a source of friction: controls are seen as obstacles, budgets are cut in times of financial pressure, and the security team is viewed as "the department of no."
Strategic alignment means that security objectives are derived from business objectives. For example:
Achieving alignment requires communication and relationship-building between the security team and business units. Security leaders must speak the language of business: risk, return on investment, competitive advantage, and customer trust. Conversely, business leaders must understand that security is an enabler of business objectives, not a barrier.
A well-governed security program provides tangible business value:
In mature organizations, the security program is not a separate "project" but an ongoing capability that is embedded in every business function. This is achieved through governance mechanisms that ensure security is considered in strategic planning, capital budgeting, and operational decision-making.
Security culture refers to the shared values, beliefs, and behaviours that influence how an organization approaches security. It is the "human factor" that determines whether security policies are followed, whether employees report incidents, and whether security is seen as a shared responsibility or as someone else's problem.
A strong security culture is characterized by:
Leadership is the single most important driver of security culture. The "tone from the top" sets expectations for the entire organization. When executives prioritize security, allocate resources, and hold people accountable, security becomes embedded in the organizational fabric.
Key leadership actions that foster a strong security culture include:
Security governance frameworks provide structured approaches to managing security risks and aligning security with business objectives. They offer a common language, best practices, and measurement criteria that organizations can use to build and evaluate their security programs.
| Framework | Primary Focus | Key Features |
|---|---|---|
| ISO/IEC 27001 | Information Security Management Systems (ISMS) | Specifies requirements for an ISMS; certification-based; risk management approach; family of standards (ISO 27002 for controls). |
| NIST Cybersecurity Framework (CSF) | Cybersecurity risk management | Voluntary framework; 5 functions (Identify, Protect, Detect, Respond, Recover); tiered maturity model; widely adopted in US critical infrastructure. |
| COBIT | IT governance and management | Enterprise-focused; links IT governance to business goals; 40 governance and management objectives; strong on control objectives and metrics. |
| CIS Controls | Prioritized security actions | 20 prioritized controls; implementation groups (IG1-IG3); actionable and prescriptive; strong on foundational cyber hygiene. |
These frameworks are not mutually exclusive; many organizations combine elements of multiple frameworks. For example, an organization might use NIST CSF for high-level risk management, ISO 27001 for certification and compliance, and CIS Controls for specific technical implementation guidance.
We will explore these frameworks in greater depth in Tutorial 6.3 (Risk Management), Tutorial 6.4 (Risk Assessment Methodologies), and Tutorial 6.6 (Security Controls). For now, it is important to understand that frameworks provide the scaffolding for governance: they define the processes, roles, and outputs that make governance operational.
In 2017, a major credit reporting agency suffered a data breach that exposed the personal information of over 140 million people. The breach was attributed to a failure to patch a known vulnerability in a web application. In the aftermath, the company's board was criticized for not providing adequate oversight of cybersecurity risks. The CEO and CISO both resigned, and the company faced hundreds of class-action lawsuits and regulatory fines.
Governance lesson: The board had delegated security oversight to management without establishing clear accountability or ensuring that security risks were reported at the board level. Had the board established a cyber risk committee, required regular security briefings, and held management accountable for remediation, the breach might have been prevented.
A global healthcare company faced a strategic decision: to accelerate its digital transformation by moving patient data to the cloud. The CISO worked closely with the executive team to design a security architecture that met regulatory requirements (HIPAA, GDPR) while enabling rapid innovation. The CISO presented a risk-based business case that showed the cost of controls was far less than the potential fines and reputational damage of a breach. The board approved the investment, and the company successfully launched its cloud-based platform.
Governance lesson: When security leaders are embedded in strategic decision-making, they can enable business objectives rather than blocking them. The CISO's ability to speak the language of risk and return on investment was critical to gaining board support.
A medium-sized financial services firm had a fragmented security culture. Employees viewed security as an obstacle, and the security team was seen as "the police." The new CISO launched a comprehensive security awareness program that included gamified training, phishing simulations, and a "security champion" network across business units. Over 18 months, the culture shifted: employees began reporting suspicious emails, security incidents were detected faster, and the security team was invited to participate in business planning sessions.
Governance lesson: Security culture does not change overnight, but with sustained leadership commitment and positive reinforcement, it can be transformed. The CISO's approach focused on empowerment rather than enforcement, which built trust and collaboration.
Test your understanding of the material covered in this tutorial. Answers are hidden below each question.
Apply the concepts from this tutorial through these practical exercises. Complete each exercise before reviewing the sample solution.
For each of the following security activities, identify which governance or management role is primarily responsible:
A mid-sized financial services firm with 2,000 employees is preparing for its first public offering (IPO). The board wants to strengthen cybersecurity governance in advance of the IPO. Design a governance structure that includes:
Recommended governance structure:
Interaction flow: Security team → SSC → Executive Council → Board Committee. Each layer provides oversight and escalates issues that require a higher level of authority.
Consider the following employee behaviours in an organization. Which behaviours indicate a strong security culture, and which indicate a weak culture? Explain your reasoning.
A software-as-a-service (SaaS) company is planning to expand into the European market. This expansion will require compliance with the General Data Protection Regulation (GDPR). The security team has proposed a set of controls to meet GDPR requirements, but the product team is concerned that these controls will delay the launch. Develop a recommendation that aligns security with business strategy.
Recommendation:
An organization has the following characteristics:
Which governance framework (or combination) would you recommend as a starting point? Justify your answer.
Recommended combination: NIST CSF for the overarching risk management approach, complemented by CIS Controls for specific, actionable technical measures, and COBIT for governance and compliance alignment.
Justification:
The combination provides strategic guidance (NIST CSF), tactical implementation (CIS Controls), and governance structure (COBIT) while leveraging the organization's existing resources effectively.
These homework questions require deeper analysis and research. Complete them independently and review the sample answers below.
Research a recent major data breach (within the last 5 years) and analyze the governance failures that contributed to the incident. In your analysis, identify:
Note: This is a sample answer based on the 2017 Equifax breach.
Write a 500-word essay arguing either for or against the following statement: "Security governance is more important than security management for the long-term success of an organization." Support your argument with evidence and examples from the tutorial and your own research.
Argument for "governance is more important": Governance provides the strategic direction, accountability, and resource allocation that enable effective management. Without governance, management activities are unfocused, underfunded, and lack the authority to implement meaningful change. The Equifax breach, for example, was not a failure of technical controls alone—it was a failure of governance to ensure that patching was prioritized and resourced. Governance establishes the "rules of the game" that ensure management efforts are aligned with business objectives and risk appetite. In contrast, management without governance can become a series of disconnected activities that fail to address the most critical risks. Therefore, while both are necessary, governance is the foundation upon which successful management is built.
Argument for "management is more important": Governance without effective management is abstract and impotent. Good governance provides direction, but it is management that executes, implements, and operates security controls. An organization can have excellent governance—clear policies, strong board oversight, and a defined risk appetite—but if management fails to implement controls, monitor threats, or respond to incidents, the organization remains vulnerable. Conversely, organizations with strong management can often compensate for weak governance by building effective security practices from the ground up, though they may face challenges in scaling and sustaining them without governance support. In practice, governance and management are complementary, and neither can succeed in isolation.
Develop a high-level security program plan for a hypothetical organization of your choice. Include:
Organization: Regional healthcare provider with 3 hospitals and 8,000 employees, serving 500,000 patients annually. Subject to HIPAA regulations.
Key business objectives: Provide high-quality patient care, protect patient privacy, comply with HIPAA, and enable telehealth services.
Governance structure: Board-level Risk Committee (meets quarterly), Executive Security Council (CISO, CIO, CFO, Legal Counsel, Chief Medical Officer), Security Steering Committee (CISO, IT, privacy officer, nursing director, finance, HR).
Management activities:
Measurement and improvement: Quarterly security metrics reported to the SSC and board, including incident counts, patch compliance, training completion, and audit findings. Annual program review and gap analysis against HITRUST CSF and NIST CSF.
Design a security culture assessment framework for an organization. Include:
Key dimensions:
Data collection:
Analysis and reporting: Aggregate data to identify strengths and weaknesses across dimensions. Compare results across departments and levels. Present findings to the SSC with actionable recommendations.
Recommendations: If leadership commitment is low, recommend executive security awareness training and public commitment from the CEO. If awareness is low, recommend enhanced training and communication campaigns. If blame culture is prevalent, recommend incident review processes that focus on systemic improvements rather than individual culpability.
Compare and contrast ISO/IEC 27001 and NIST CSF as governance frameworks. In your analysis, address:
| Aspect | ISO/IEC 27001 | NIST CSF |
|---|---|---|
| Primary objective | Certify an ISMS; demonstrate compliance to stakeholders | Provide a voluntary framework for managing cybersecurity risk; improve resilience |
| Audience | Organizations seeking certification; regulated industries; global businesses | US critical infrastructure; federal agencies; any organization wanting a risk-based approach |
| Risk approach | Risk assessment and treatment required; prescriptive control set (Annex A) | Risk-based, but allows flexibility in selecting controls; not prescriptive |
| Structure | Clauses 0–10; Annex A with 114 controls; management system approach | 5 functions, 23 categories, and subcategories; implementation tiers; profiles |
| Certification | Yes – third-party certification available | No – self-assessment or third-party "alignment" but no formal certification |
| Preferred scenario | Regulatory compliance, contractual requirements, global recognition | US federal agencies, critical infrastructure, organizations seeking flexible guidance |
Conclusion: ISO 27001 is preferred when certification is required or when a formal, auditable ISMS is needed. NIST CSF is preferred when flexibility and alignment with US government frameworks are desired, or when the organization wants a high-level, risk-based approach without the overhead of certification.
In this introductory tutorial, we established the foundational concepts of security management and information security governance. We learned that governance provides strategic direction, oversight, and accountability, while management executes the plans, processes, and controls that operationalize security. Both are essential for a mature security program.
We explored the security program lifecycle using the PDCA model, which emphasizes continuous improvement and adaptation to evolving threats. We examined the governance pyramid, from the board of directors down to operational security teams, and identified the distinct responsibilities of each layer. We also discussed the critical role of security culture and leadership in creating an environment where security is a shared responsibility.
Finally, we surveyed the major governance frameworks—ISO 27001, NIST CSF, COBIT, and CIS Controls—that provide structured approaches to building and evaluating security programs. These frameworks will be explored in greater depth in subsequent tutorials, where we will apply them to risk assessment, control selection, and compliance management.
As you progress through Unit 6, remember that the concepts introduced here—governance, management, accountability, culture, and strategic alignment—are the threads that connect all of the topics we will cover. Whether we are discussing risk assessment, incident response, business continuity, or legal issues, the governance and management principles you have learned in this tutorial will provide the context that makes those topics meaningful in practice.
COMP400 — Computer and Network Security (Revision 3) • Unit 6.1 • © TrustOpen University