TechKnowSurge
NIST CSF GV.OC-01 NIST CSF GV.OC-02 NIST CSF GV.OC-03 CompTIA Security+ 5.1 NIST 800-53 PL-9 NIST CSF GV.RR-02 ISC2 CISSP 1.3
VideoSecurityFree

Security Program Governance

Building an effective cybersecurity program requires understanding what drives the need for one, who owns it organizationally, and how it gets structured across the business. This content covers the internal and external pressures that prompt security investment, the role of executive support, and the differences between centralized and decentralized program governance.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cybersecurity programs demand significant time, money, and organizational resources, which means the decision to build one is rarely made without clear justification. The forces behind that decision fall into two broad categories: external drivers, such as increasingly demanding customers, stricter laws and regulations, and rising cybersecurity insurance requirements, and internal drivers, most commonly a security incident or breach that creates enough pain to force change. In practice, most organizations find themselves responding reactively to one of these pressures rather than acting proactively — but a proactive approach delivers measurably better outcomes, reducing both risk exposure and long-term costs before an incident occurs. The stakes are high: 60% of small and medium-sized businesses fail within six months of a cyberattack, making early investment in security a matter of organizational survival. Once the decision to build a program is made, securing executive support is essential. Cybersecurity initiatives require budget, authority, and organizational buy-in that can only come from leadership. Depending on the size and structure of the organization, program ownership may sit with a Chief Information Security Officer at the executive level, a director or manager who develops policies and seeks sign-off from senior leadership, or a cross-functional committee that spans multiple levels of the org chart. Boards of directors and CEOs are also taking a more direct role in cybersecurity oversight than in previous years as the topic has grown in visibility and consequence. How a program is governed and rolled out also varies based on organizational structure. A centralized model places policy development and enforcement authority at headquarters or a single governing body, applying consistent standards across all locations and departments — an approach that works well for larger organizations focused on stability and risk management. A decentralized model delegates security responsibilities to individual sites, departments, or business units, offering greater flexibility and agility, which tends to suit smaller or faster-moving organizations. In practice, the right approach depends on the company's size, industry, regulatory environment, and operational complexity, and effective security governance means adapting the program structure to fit the organization rather than applying a one-size-fits-all model.

What you'll learn

What's covered

Security Program Development

Aligned to

NIST CSF
GV.OC-01 The organizational mission is understood and informs cybersecurity risk management.
GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered.
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced.
CompTIA Security+
5.1 Summarize elements of effective security governance.
NIST 800-53
PL-9 Central Management
ISC2 CISSP
1.3 Evaluate and apply security governance principles

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Security Operations Center
SOC
A centralized team and facility responsible for monitoring, detecting, and responding to security incidents.
Cybersecurity Program
An ongoing organizational function that encompasses risk assessment, policy development, regulatory compliance, employee training, and accountability to protect the organization continuously.
Internal Drivers
Forces originating within an organization, such as a past security incident or leadership mandate, that motivate the development of a cybersecurity program.
External Drivers
Forces outside an organization, such as customer requirements, laws and regulations, or cybersecurity insurance requirements, that compel the development of a cybersecurity program.
Centralized Security Governance
A model in which security policies and procedures are set by a single authority and applied consistently across the entire organization.
Decentralized Security Governance
A model in which security responsibilities are delegated to individual departments, sites, or business units rather than managed from a single central authority.
Chief Information Security Officer
CISO
The senior executive responsible for establishing and maintaining an organization's security vision, strategy, and program. The CISO manages security risk across people, processes, and technology and communicates security posture to executive leadership and boards.

Topics

Security Governance Cybersecurity Program Management Security Leadership Centralized Vs Decentralized Governance Regulatory Compliance Executive Sponsorship

Transcript

Developing a comprehensive security program takes a lot of time, energy and money to do. It eats up a lot of resources, so we don't want to just do it to do it. There are certain reasons why we do it, but what are the driving forces?

Drivers of change

I found that there's these certain drivers that keep coming up again and again to drive change when it comes to a cybersecurity program, and they can be categorized into two different categories here. One is just internal: internally we've decided this is a change that we need to do. Versus external: there are a lot of external factors that I find.

Number one is just customers are becoming more and more demanding around cybersecurity, and if you don't meet the customers' needs, they're going to cease to be customers. They're going to move to other companies. Or what I found is a lot of customers won't even become a customer of yours until you meet certain cybersecurity changes, until you implement certain cybersecurity policies, or until you implement certain controls. So that's one thing that's increased over time.

Another thing that's increased is the laws and regulations. They're getting a lot more stiff, and the bar is being set high with these. Same thing with cybersecurity insurance: in order to get insurance nowadays, it's becoming a lot more requirements to even get a quote for cybersecurity insurance with this.

The other thing that I find is a common driver, if it's internal, is that we've encountered some sort of pain point. That is, somebody hacked something, or there was a compromise, maybe there was a scam. Something's happened, and now we say, oh, that was really painful, so now we need to make some changes.

Reactive versus proactive

So really, most of the time that I find with cybersecurity is that we play a reactive role. That is, we make a change because, once again, we've experienced some sort of pain, or there's some sort of external influence that's making us make this change. But what we really need to do is get more on the proactive side, and it really makes a lot of sense to do that. Because the reason why the customers and the laws and regulations and cybersecurity insurance, the reason why the standard around these are growing, is because they're protecting customers, and we want to protect customers as well.

Not only do we want to protect customers, but we want to protect the business. If we find ourselves in a cybersecurity incident, 60% of small businesses, small and medium-sized businesses, go out of business within six months after a cyber attack. That's pretty staggering. So if we take that proactive stance, we actually create a much more stable, reduced amount of risk, reduce the amount of cost to the company, if it's done right.

Upper level support

Now, ultimately you're really not going to get very far unless you've got upper level support. What do I mean by that? Here's the corporate structure. At the top of a corporation, at least, you have a CEO, and then underneath there you have this group of execs you call the C-Suite. Then you've got the VPs, under there you've got the directors, managers, and then individual contributors. You need the support from the upper management in order to carry out a lot of the stuff that you need to carry out, because there is a lot of time and energy and resources that go into creating a cybersecurity program.

Although many see the CEO as being the top of the company, the CEO really reports to the board of directors, who elect the CEO, and the board of directors are elected by shareholders and company owners. So there's kind of a structure to this, and you need the support from all of this.

Who approves the program

But who's actually in charge of approving the cybersecurity program and the policies, and what does that look like? This can look different depending on the company. For instance, if you're a larger company, you have somebody like a CISO, which is a chief information security officer, that operates at the C-Suite, who really is the driver to a lot of this.

What I've also seen is at smaller companies, like I was a director for a company, and as a director I would then create all the policies but then get sign-off from the upper execs to make sure that everybody was on board with it.

I've also seen things driven more from board of directors and CEOs more so than I ever have in the past, because cybersecurity has become a very hot topic. So now you see a lot, much more so than I ever seen before, you've seen a lot of requests coming now from the top.

Another way we could also do this is create a committee, a committee maybe of individual contributors, managers, directors, VPs, C-Suites, or really it could be any combination of any of these. So we might create a committee to either develop or approve of these policies. And some of them are policies that are just put on us from a legal perspective, that we're just required to implement.

Centralized and decentralized

The way we roll out a security program and the policies and the procedures might look different also from a centralized or decentralized. What does that mean? This could be centralized or decentralized based off maybe geographical locations, or departments. There's a lot of different ways we could roll this out, but I'm going to use geographical just because it gives us a nice visual.

Let's talk about decentralized first. Let's say the company has a headquarter office here in Seattle. We have a satellite campus over in Chicago. We've got several buildings over in the New York area, and then we've got a factory that's down in Texas. Decentralized just means that maybe we have some upper level policies, but for the most part all of these sites kind of is in charge of their own security. That is decentralized.

Versus a centralized system means that there's going to be a central control around security. So with a centralized system, let's use headquarters as an example here. Headquarters here sets the tone, sets the policies, the procedures and everything, and then it's a requirement for all of these other sites to follow that.

So a centralized system is maintained organization wide, versus decentralized is delegated: some of these tasks are delegated out to the individual offices, or individual departments, or whatever the case may be. Centralized gives us some level of consistency amongst the organization, versus decentralized allows us to be much more dynamic. And then generally the centralized works with larger companies, because they go from a growth state to more of a protection state, versus a decentralized is more for smaller companies, at least what I found, because they're more into being agile and being able to adapt and dynamically change.

Ultimately there's going to be a lot of different ways that we roll this out and how we structure this, but the big thing is that we need to adapt to the company, the size of the company, the industry it's in. And how we govern our security operations and our policies is really going to change depending on what the needs of that organization or that company are.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →