Guidelines for Applying Security Governance Principles ▪ Consider CIA triad when securing information and other assets. ▪ Balance need for availability with needs for confidentiality and integrity. ▪ Establish clear chain of organizational governance. ▪ Security and business operations must align to be effective. ▪ Decision makers must understand that security is not an after-thought. ▪ Ensure security is incorporated into major business processes. ▪ Ensure each job role is clearly defined and positioned relative to security needs. ▪ Know roles and responsibilities of a CISO. ▪ Communicate security concerns to decision makers clearly and understandably. ▪ Listen to concerns and advice of others. ▪ Establish a security reporting structure. ▪ Create or adopt a security control framework. Always exercise due care and due diligence