Transcription
Compared to other security leadership exams, the CISM trends more toward the strategic and a bit less technical. And nowhere is that more apparent than in Domain One: Information Security Governance. So here in Part A, we're going to focus on enterprise governance, types of compliance, organizational culture, structure, roles, responsibilities, and accountability. And many of the concepts we discuss here may be a little more than buzzwords for you if you're more technically focused as an exam candidate, but they will be concrete concepts for you when we're done. So regardless of where you are today, we'll look at the key topics of Domain 1A through the lens of CISM exam readiness to ensure not only do you know them, but you understand them. And with a little practice, you'll never forget them.
Welcome, or welcome back, to my CISM exam prep series where today we'll be covering every line item in the exam syllabus for Domain One, Part A, which is Enterprise Governance. And while you may know me for my exam prep content here on YouTube, in my 9-to-5, I'm a cybersecurity strategist and a VC for a regional bank where I'm exercising my cybersecurity knowledge every day, like that which you'll find here on the CISM exam. More importantly, last year I helped thousands achieve cybersecurity certifications like the CISSP, CCSP, and the Security Plus exams, and I'm bringing that proven formula to you here with the CISM exam. As with all my exam prep courses, you'll find a PDF copy of this presentation available for you in the video description to leverage in your exam preparation as you require. You'll also find a clickable table of contents available in the video description, and it should appear automatically on your YouTube video timeline.
In the CISM exam syllabus, there are four domains. We're going to begin in Domain One, which is Information Security Governance. And what you'll find is each of these four domains are broken down into two parts, into a Part A and a Part B in the syllabus. So today, we'll begin with Domain 1A, which is Enterprise Governance. Now, if you missed the kickoff of this series, the series intro and exam prep strategy, I recommend you go back and watch that video so you understand how to best leverage this series as you prepare for the CISM.
So here in Domain One, which is Information Security Governance, we'll begin with Part A, Enterprise Governance, which consists of three subsections: organizational culture, legal, regulatory, and contractual requirements, and then organizational structures, roles, and responsibilities. There's quite a bit of foundation material here that gets folks tripped up when they get to the live exam. So the concepts we cover here are going to be a foundation that you use throughout the four domains. This will be followed by Part B, which is Information Security Strategy, which consists of strategy development, governance frameworks and standards, and strategic planning. You're going to see very heavy focus in this domain, a very logical flow from governance to strategy as you'll see as we move through, but a heavy focus on alignment with business needs. Remember, security is all about supporting the business and aligning with business objectives.
So let's have a look at the first section of Domain 1A, which is 1A1 Organizational Culture. We're going to dig into the relationship between enterprise governance and information security governance. We'll look at the principles of governance, the expected outcomes of governance. I want you to understand the purpose and relationship between the scope and charter of our governance program, the relationship between infosec, IT security, and cybersecurity. And we'll wrap up with a look at organizational culture, as well as acceptable use and how we implement our acceptable use policy. And while you'll grow weary of hearing it, you'll be glad to know it on exam day: remember, governance should guide a strategy that aligns with business needs. It's all about the business. You're going to want that in the back of your head every time you're looking at a question on the CISM exam or on any of the practice exams.
Now, along with that syllabus, there is a list of 37 what ISACA calls supporting tasks. I will share the bits and pieces of those 37 supporting tasks in their most appropriate domain. So today, I'll just lay out here task number four: Integrate information security governance into corporate governance. Basically, enterprise governance equals corporate governance for purposes of our discussion. Task eight: Define, communicate, and monitor information security responsibilities throughout the organization and lines of authority, roles, and responsibilities, and responsibility versus accountability will be our focus here. And task 21: Identify legal, regulatory, organizational, and other applicable compliance requirements. And remember, legal and regulatory requirements are the most important drivers of the need for compliance. And the great news is, by the time we finish this session here on Domain 1A, you'll have the knowledge you need for these three supporting tasks well in hand.
I'd like to give you a preliminary definition of three important terms that we're going to explore at greater depth throughout Domain 1A. Those are: Governance, which ensures the needs of various stakeholders are evaluated to determine balanced, agreed-upon enterprise objectives. The objectives are then used to set direction through prioritization and decision-making, and to monitor performance and compliance on an ongoing basis. If I were to summarize it, governance is about direction and oversight. Strategy defines the desired state of security for an organization, aligning with its business objectives. It outlines a roadmap for achieving this desired state by addressing identified risks and vulnerabilities. That roadmap, it's charting the course. And management implements directions set by governance, following the roadmap set by strategy. It includes planning, building, operation, monitoring, and managing operational risk tolerance. So we see a very clear flow between these three processes, and that direction comes from the top down. So we see that coming from the top of the organization down to our engineering.
So let's have a look at governance from two perspectives. We have Enterprise Governance, which is the overall framework of rules, policies, standards, and procedures that direct, monitor, and control all activities across an organization. It covers the organization's objectives, vision, mission, organizational structure, and leadership. It ensures security risks and business risks are managed cohesively. They are considered together as a whole. We then have Information Security Governance, which is a specialized subset of enterprise governance focused specifically on protecting the organization's information assets. Information security governance ensures that security policies and practices are integrated into the business. And in fact, information security governance leverages enterprise governance structure to embed security into every aspect of the organization.
So let's talk for a moment about planning horizons. This goes a long way to helping us appreciate the focus of the different roles within our organization. And if we work from the top down, the focus of our executives tends to be strategic. They're looking on a three-to-five-year timeframe at the long-term goals of the organization. And as we move down the org chart in the manager and director area, we're a bit more tactical. They're looking at more on a one-year timeline, managing budgets, wearing multiple hats, both business and technically focused. And working our way down to our technicians, who are really working day-to-day. The operational objectives will typically be running on a one-to-three-month timeframe. And familiarity with these planning horizons, with the relative focus of members of the organization from the top down, can be very helpful on exam day to help you to choose a role-appropriate answer from the options you're given for any specific question. Questions will often involve specific roles within the organization. If you know their focus, you're going to be able to choose an answer that maps to the focus of that role.
All right, so we have section 1A1 Organizational Culture. A number of topics to go through here. I'd like to start with some quick definitions again, just to help you from the outset. And these three are: Accountability, which is the obligation to answer for one's actions, decisions, or results. Perhaps the most important thing to remember about accountability is it cannot be delegated. It rests with the person who originally assigned the task. This will be a single person or entity. There's going to be one person, one entity accountable. Then Responsibility is the duty or obligation to complete a task or achieve a specific goal. Responsibility can be delegated to others to do the work, but the person who delegates still remains accountable for the overall outcome. And responsible may translate to multiple people. We may delegate a task to a team of people, in fact. And the span of control speaks to the number of subordinates that report to a manager or that a manager can effectively supervise. By most accounts, less than 10 is best on a team.
Okay, we're going to dig a bit deeper into information security governance. These are top-down activities that help management understand and control the organization's security program, current risks, and initiatives. It ensures security program and initiatives align with and support business objectives. There's that business alignment again. It translates strategic objectives into actionable policies, controls, and metrics, but the focus here is very high-level and coming from leadership. The most important objective of information security governance is to ensure that the information security strategy is in alignment with the strategic goals and objectives of the business. A top-down approach to governance and management is considered critical because it means the necessary executive-level insight and support is present and behind the effort. You may see questions on that very topic on the exam. The top-down approach is what we're looking for.
So we've talked about governance, strategy, and management. I want to dig into the difference between these from another perspective to make sure you're crystal clear. It's going to be very important for the exam. So governance establishes the overall security vision and risk appetite. It defines policy, standards, and frameworks we're going to use. It sets the "why" and the "what" that we're going to aim for. We have strategy, which translates governance directives into actionable plans. It identifies and prioritizes initiatives, and it defines the roadmap. Make sure you associate roadmap with strategy in your mind. It defines the "how" at a high level. And management executes the "how." It implements and maintains security controls. It manages day-to-day security operations.
So let's establish some clarity around alignment with business objectives. So business alignment means ensuring the information security program integrates seamlessly with the overall organization, that there's no conflict. And to understand business alignment with the organization, you need to understand two key areas: the organizational foundation. So what is the organization's mission? What is its purpose? Who does it serve? What are the established goals and objectives that have come down from leadership? What needs to be achieved and when? Strategic approach. What specific activities are needed to meet these goals? Remember, when we move from governance into strategy, strategy outlines the roadmap, the activities, and then we need to understand key business factors. We need to understand the corporate culture, the value of our assets, our competitive market position, regulatory and legal requirements to make sure that the security that we are implementing, that our program, secures the business without hindering the business.
So let's unpack some of those organizational foundation terms. There's Vision, which is a clear, aspirational statement of the desired future state of the organization's security posture and capabilities. So what does the organization aspire to deliver? For example, if we go to the Microsoft website, their vision statement is to democratize AI, making it accessible and beneficial for everyone. Very aspirational statement. Then we have the organization's Mission, a concise declaration of the organization's core purpose in implementing and maintaining security measures and identification of key stakeholders being served. Let's go back to Microsoft again. What do we want to do? What is our core purpose? Microsoft says their core purpose, their mission, is to empower every person and every organization on the planet to achieve more.
So let's dig into strategic objectives. These are specific, measurable, and time-bound goals that outline the path toward achieving the security vision while aligning with organizational priorities. So how are we going to progress? What are our plans? Our goals? And the sequencing, the roadmap implementation? And KPIs, that's the tactical implementation plan consisting of specific tasks and assigned responsibilities. KPIs are the measurable metrics that demonstrate progress toward strategic security objectives. So what do we need to do, and how do we know when we've achieved it?
The ISACA Code of Professional Ethics is considered testable on the exam. There's a list of seven. I've summarized them for you here. This should be enough to get you by on exam day. I certainly don't expect you're going to see more than one question. So:
1. Support the implementation of and encourage compliance with appropriate standards and procedures.
2. Perform their duties with due diligence and professional care in accordance with professional standards.
3. Serving the interest of stakeholders in a lawful and honest manner while maintaining high standards of conduct and character. A lot of very common sense tenets here in the professional ethics so far. Pretty common sense, I think.
4. Maintain the privacy and confidentiality of information obtained in the course of their duties. There is an asterisk by this, which I'll explain in a moment.
5. Maintain competency in their respective fields and agree to undertake only those activities they can complete competently. So part of honesty and integrity is admitting when we are not competent in an area and then thus not undertaking that activity.
6. Inform appropriate parties of the results of work performed, revealing all significant facts known to them.
7. Support the professional education of stakeholders in enhancing their understanding of security governance and management.
I've summarized these a bit. You can certainly go read the longer list. I don't believe it's necessary for the exam. Now, I mentioned there's a bit of an asterisk by number four: Maintain the privacy and confidentiality of information obtained in the course of their duties, unless the law requires you to do otherwise. So if you were presented with a situation on the exam where the law required you to reveal confidential information of a customer, if the law requires you to do that, then you must do that.
Moving on to the importance of information security governance. What are the key benefits that we achieve from information security governance? What's in it for us in exchange for all that effort? Well, governance reduces liability, it protects the organization and its leadership from legal and civil repercussions due to data breaches or non-compliance. It ensures compliance, it helps the organization adhere to the policies and regulatory requirements that it's beholden to. It manages risk, it lowers operational uncertainties by identifying and mitigating risks to acceptable levels. And it helps optimize resources, it provides a framework to allocate security resources effectively, which from a leadership perspective means not only technically effective but also economically effective.
So let's talk about the six basic outcomes of information security governance defined by ISACA. The first is strategic alignment, so security strategy supports business objectives. Solutions are tailored to the organization. Basically, investments aligned to business strategy. We have risk management, so a shared understanding of the organization's risk profile, so we're all aimed at the same target when it comes to mitigating risk. Proactive identification and mitigation of our risks, essentially keeping risk within the organization's risk tolerance level. Value delivery, so security practices are standardized and proportionate to the risk. Resources are prioritized, and security overhead is minimized. Solutions are cost-effective, and continuous improvement is part of the program. Effectively, how do our investments in security contribute to the bottom line? How is security delivering value to the business? Fourth on the list is resource optimization. Knowledge is effectively captured and disseminated. Processes are formalized in IT policies and procedures. Basically, resources have to be used efficiently. Performance measurement, well-defined metrics aligned with strategic objectives. Independent assurance through audits and assessments. You can't manage what you can't measure. It's through effective measurement that we understand how we're progressing toward our goals. And then assurance process integration, so coordination of all assurance functions within the organization. Clear roles and responsibilities to avoid gaps or overlaps. But bottom line, a holistic approach. Security is not a siloed function.
Now, you might not be familiar with this phrase, assurance process. So let's put a definition and some examples to the phrase. Assurance processes are the systematic methods and activities that confirm to the organization's stakeholders that security controls and policies are effectively implemented, operating as intended, and aligned with the organization's overall risk management and compliance goals. So a few examples of assurance processes: risk assessments, security audits, vulnerability scans, penetration testing, compliance reviews. They provide demonstrable assurances to the organization that our security controls are in place and doing what they need to do.
So let's talk about scope and charter. So the charter specifies who has the power to act, what they are responsible for, and why the information security program exists. Scope defines where, to whom, and to what extent the information security program applies. So generally speaking, most organizations have a single security charter that includes both governance and operational aspects alongside a clearly defined scope. So they're consolidated into a single document. The charter defines authority and objectives, and the scope defines coverage and boundaries.
I want to touch on three security disciplines to make sure you understand their scope and the relationship between the three. The first is Information Security, this is the broadest of the three and it covers all forms of information regardless of format or location. So that would include not only digital assets but even sensitive information in paper form. We then have IT Security or Information Technology Security, that's a subset of information security focusing specifically on protecting information within the technology itself. So that's digital information we're worried about. And finally, Cybersecurity, which is a subdiscipline of information security that focuses on protecting connected systems from cyber attacks.
Next, let's talk organizational culture, which refers to how employees work and interact. So security isn't about technology alone. It definitely involves the people and how they behave, how they use the technology, how they respond. So key influences on culture in the context of this exam, we're talking about transparency and accountability, formal and informal structures in our organization, the attitudes and norms of behavior, the level of teamwork in an organization, and individual backgrounds or skill sets and their work ethics. So these can be positive or negative, and a security-aware culture is absolutely essential for success. For example, with phishing emails, with phishing attacks, there are two things we can do to reduce the frequency or the likelihood that we're going to succumb to a phishing attack: one is showing that employee fewer phishing emails, the other thing we can do is train that employee to recognize that malicious email and not click on anything in that message. And for the CISM exam, we want to remember that these elements of culture take time, effort, and explicit support from leadership.
The organizational structure of the org chart is important because it establishes roles and responsibilities. We do need that responsibility and accountability clearly defined. But in the most effective organizations, we see a bit of informality in that folks take ownership of the outcomes. We see more collaboration and a security-aware culture where everyone takes responsibility for security is really what we're aiming for. And the tone from the top of the org chart, from leadership, helps establish that direction that results in a strong organizational culture that is security-aware, where everybody takes that ownership.
So let's talk about the security manager role because the security manager requires both technical and interpersonal skills. You'll commonly hear that the security manager wears multiple hats. They need to be able to build relationships and influence behavior, and they need to tailor their communication to address the individual needs and concerns, whether they're talking to employees or team members, and really help folks understand, you know, what's in it for me if I do what you say or get on board with what you're suggesting. So indicators of a positive security culture would be where security is integrated into projects early on. We often see this discussed in the context of DevSecOps, where employees know how to report incidents because they're taking that accountability, they understand that they have a role in protecting our company's sensitive information, our valuable assets. So for the exam, know that the security manager's role in developing a positive security culture takes time and effort, and they're wearing those two hats. They have some technical know-how, but they also have strong interpersonal skills if they're going to be effective in their role.
Next, we have the Acceptable Use Policy. So the Acceptable Use Policy is a formal document. It outlines permissible activities and prohibited activities for individuals that are interacting with our organization's information systems and our sensitive data. So the scope is not just employees, it applies to anyone who uses or handles the organization's information. That can be employees, contractors, or even third parties, but it's anyone touching the organization's information assets. So it covers aspects like access control, data classification and handling, reporting incidents, disclosure constraints in confidentiality situations, as well as mobile device usage. Typically, we're going to have a mobile device policy like Bring Your Own Device, and we'll outline acceptable use in that context. But key elements of a good acceptable use policy will include permitted and prohibited activities, consequences of violations, roles and responsibilities, and communication and awareness. And typically, recipients will need to sign to acknowledge agreement to those terms of acceptable use.
The key element here is we're looking for some activity that directly influences alignment between information security and business functions. So right away, there are a couple of these I can cross off. Providing funding for information security efforts, while it may improve our information security program, there's not a direct indication there that it's going to improve alignment between infosec and business functions. I'm going to cross off establishing a security awareness program. A security awareness program can help us to build a security-aware culture. It's not necessarily doing anything directly to improve alignment between information security and business functions. That leaves us two pretty good options here: developing information security policy, so basically documenting our expected alignment between infosec and business, and then I have establishing an information security governance committee. So if we go back to our discussion of governance at the beginning of this module, module 1A, we talked about governance having a strong focus on aligning security and business functions, so that security must help the business. And so my guess is going to be C. And in fact, the answer here is C, establishing an information security governance committee, because we're involving key stakeholders from different business functions. That committee is going to facilitate top-down collaboration, communication, and decision-making that promote that integration of information security into the organization's core business processes. And because that committee has governance in the name, it was likely formed under the direction of the board of directors or the CEO, so it's from its very inception going to have a strong element of business-security alignment.
Okay, let's move into Section 1A2 of Part A here, which is Legal, Regulatory, and Contractual Requirements. Here we'll touch on the concept of compliance and compliance requirements, identifying applicable compliance standards to our organization, legal compliance requirements, regulatory compliance requirements, and requirements for content and retention of business records. So compliance can influence the period of time for which we need to retain certain business records. Exiting this module, you want to make sure you know the drivers of compliance and know which take precedence, which take priority over others.
So before we go any further, there are a couple of important terms you should be familiar with. The first is compliance. So this is an organization's adherence to the laws, regulations, standards, and contractual obligations that govern its operations. So this would involve implementing policies, procedures, and controls to ensure that all the organization's activities meet these established requirements, whether they are implemented in law or through regulations, such as if we're in the healthcare industry, regulations that govern our industry, or our contractual obligations between our organization and a customer, or an organization and its vendors. These could be legal, they can be regulatory, or contractual. We'll dig into all three. And then there is due diligence. These are the reasonable steps an organization takes to identify, assess, and address cybersecurity risks. This would involve proactively evaluating an organization's networks, our systems, and our data to uncover vulnerabilities and to implement controls that protect against these threats. An example would be auditing our IT infrastructure, testing our incident response plans to make sure they work, or implementing security awareness training.
So let's talk through the three types of compliance requirements. First, we have legal, which are imposed by laws passed by government bodies and apply broadly to all organizations within that jurisdiction. For a state law, for example, that would be within the state. A federal law would mean all organizations within that country. So for example, the California Consumer Privacy Act. It's a state law enacted to enhance privacy rights and consumer protection for California residents. Then there's regulatory requirements. So regulatory compliance is imposed by regulatory bodies or government agencies to implement and enforce laws. They're enforced by regulatory agencies through audits and fines. So administrative law, not criminal, generally speaking. So examples here would be HIPAA, which covers healthcare, FERPA, SOX, or Sarbanes-Oxley, which affects public companies in the United States, and then GDPR, which is privacy protection in the EU and considered the gold standard. And then we have contractual, these are imposed through legally binding agreements between organizations. Basically enforced through contract terms and potential legal action. So they're written into vendor agreements, for example. A great example of this is PCI DSS, which are payment card requirements that are written into contracts by the big four credit card companies for any payment processors. It's a regulation commonly seen as a regulation, but it's actually not implemented through regulation or law. It's implemented through contracts between the credit card companies and the card processors.
Let's talk through how we identify applicable compliance standards. So there are certainly regulated industries that have to comply with certain regulations. For example, the healthcare industry has to comply with HIPAA. The banking industry has multiple regulations, including Gramm-Leach-Bliley, for example. And it's going to be a combination of the industry and the country in which that entity is located. For example, HIPAA is a healthcare law in the United States. Now, data processing activities may necessitate compliance with regulations such as HIPAA or GDPR, which is data privacy for any company with customers in the EU. So PII, personally identifiable information, things like name, address, social security number, etc. And then PHI, which is protected health information. Customer contracts and agreements. So some contracts may mandate compliance with certain standards. For example, there's a big tech company that requires all of their contractors to be ISO 27001 certified. And you can consult with legal and compliance experts if you're unsure which regulations might apply to your business. If you have in-house legal counsel, they can certainly help, or perhaps you go out and find an external expert in regulation for your industry or outside legal counsel if you don't have it in-house. And you can utilize compliance frameworks. Organizations do this all the time because they provide guidance on implementation of a secure information security program in various respects, often specific to certain types of organizations. And regulations may change over time. So our organization has to stay updated on regulatory changes. And that means the responsible roles have to be aware of any changes in our regulatory obligations the organization must adhere to, because that may necessitate changes in our policies, processes, and security controls. Conducting regular compliance assessments. So gap analysis and risk assessments can identify areas where the organization may not be fully compliant, so we can close those gaps. But important activities that support the organization's compliance include documenting our compliance program, training our employees. We need a security-aware culture, but we need employees that are aware of our regulatory obligations. Implement strong security controls that meet our compliance obligations. Monitor and audit to make sure those controls remain in place and effective. And respond to incidents promptly. And responding to incidents may include notification of customers in cases where we have an incident that results in a data breach, we have to notify affected customers within a certain period of time.
So let's talk about factors in business record handling. So business record requirements include legal and regulatory mandates for the creation, storage, retrieval, retention, and disposal of business records. This is going to be relevant to many different types of media, including email communications, financial documents, employee records, and several more. And different jurisdictions may have specific regulations that dictate various aspects of record handling. This could include how long records must be kept, the retention, under what conditions they can be destroyed or released to external parties. And some of your key considerations in determining those retention requirements can include regulations, for example, Sarbanes-Oxley requires that companies who must adhere to SOX keep their financial reports for seven years. Risk management. If we have the detailed elements of a security incident, we might keep those logs for a period of time so we can go back and revisit that in light of any pending litigation or investigations. Now, pending litigation brings some special requirements. If we have records that are included in legal proceedings, they're generally going to be subject to a legal hold if it's been requested that the organization produces those records, in which case they may need to be held indefinitely until that legal proceeding comes to its natural conclusion.
Okay, so here at the end of Section 1A2, I'd like to go through a practice question so we can apply what we've learned. So the question is: What is the primary driver for information security governance that requires no further justification? Our options are: business benefits, alignment with industry best practices, business continuity investment, and regulatory compliance. So we're talking about information security governance, and the key factor here is which of these drivers requires no further justification. So there are a couple of these I can mark off right away. So alignment with industry best practices is always going to be a secondary factor. I can certainly try to align with industry best practices, but if I need to tailor my governance and my security program to my organization and that requires me to drift outside of industry best practices to meet my requirements, I'm going to do that. Business continuity investment, uh, we're certainly going to have some objectives we set for the business around critical services that may establish our RTO and RPO, our recovery time and recovery point objectives, but there's certainly going to be room for discussion there. And that leaves me with two options here: business benefits and regulatory compliance. So when I look at these, business benefits are always going to be a key focus of my governance efforts. When I'm looking at information security, I'm always trying to align with the business, but there's going to be some room, wiggle room there, there's going to be some room for discussion. Now, when I look at regulatory compliance, that comes from government and regulatory entities through law or regulations. I don't have a lot of choice there. So my answer is going to be D, regulatory compliance. And that's a standalone driver that requires no further justification because as an organization that must adhere to those requirements, such as HIPAA for healthcare organizations, the entity has no choice but to comply with those requirements. So we don't need to discuss it, we just need to do it. So a key takeaway for exam day is remembering that legal and regulatory compliance are going to be the highest priority because the organization has no choice in the matter.
Okay, moving on to section 1A3, which is Organizational Structures, Roles, and Responsibilities. So we'll look at roles and responsibilities right out of the gate, and then we're going to go through some of the common job titles and their typical responsibilities, and then we'll move into some areas that transcend job roles. So we'll talk about risk management, we'll talk about business process owners and the steering committee, then we'll wrap up with a look at the RACI matrix and some keys to a successful implementation of RACI. So for the exam, you want to make sure that you know who is responsible and who is accountable in all situations. So we'll touch on that again here in a moment. And do you want to make sure that you're familiar with those functions that transcend job titles, functions that may be assigned to specific roles but not the same job title in every org?
So let's take a look at a couple of important terms here. We're going to start with roles and responsibilities. So roles are high-level positions or job titles. So for example, project manager, developer, designer, marketing manager, CEO. Those are roles, those are job titles. Then we have responsibilities, so these are specific duties and tasks associated with each of these roles. So for example, a developer's responsibilities might include coding, testing, and debugging.
Okay, let's go through common organization structure roles and responsibilities. Certainly, it can vary by organization. I'm going to stick to what ISACA touches on in terms of common roles and common responsibilities that should give you what you need per exam day. So these are common organizational roles and responsibilities. They'll give you what you need for exam day, recognizing that some are security-focused roles, some are more business-focused roles, and that the titles and responsibilities can vary a bit across organizations. All aim for alignment between security and business goals. Remember, one of those elements of security governance is value delivery. How does information security benefit the business? How are we contributing to the bottom line?
So let's start with the Board of Directors. This is the highest governing body in the organization. They oversee all organizational activities. They hold ultimate responsibility for the organization's success. We could say they are accountable for the organization's success. Accountability is ultimate responsibility. They have a fiduciary duty to act in the shareholders' interest. They are protecting shareholder value. So their duties will include selecting the CEO and firing that CEO, setting risk appetite, forming oversight committees, providing strategic guidance to the organization, and approving organizational decisions.
Then we have Senior Management, which could encompass a variety of senior management roles, the C-suite, for example. Duties here will include ensuring board intentions are implemented from governance on down, governance, strategy to management, making sure that it happens, supporting information security projects with budget and resources, guiding balanced decision-making in security matters, ensuring business alignment with security.
Then our Chief Executive Officer, our CEO. This is the top-ranking executive, reports directly to the board of directors. They are responsible for all aspects of the organization's success. So they are delivering on the board's intentions. So duties here will include developing governance functions, managing organization assets, budget, and personnel, overseeing risk management at the highest level, and executing on board directives.
Our Chief Information Security Officer, or CISO. They're responsible for the information security program and strategy, developing, implementing, and enforcing security policies, managing our risk programs, overseeing security operations. So you see they have very much a security-focused function, as the job title dictates, but they are also ensuring security alignment with business goals, making sure that security benefits the business, contributes to the bottom line, does not hinder the conduction of business.
Chief Privacy Officer. So this role is responsible for the organization's privacy program, including protection of sensitive information. This role will be very focused on oversight of personally identifiable information and advocating for privacy of consumers or customers, and coordination with the CISO on information protection.
We have the Chief Risk Officer. This role is responsible for overall enterprise risk management. This often includes information security-related risks, but it's always going to include business-related risks. In the banking industry, they'll focus on minimizing fraud and financial transactions. In fact, Chief Risk Officer is a role I very commonly see in the banking sector.
So risk management. This is an area that transcends job titles. So there are two key roles here: there's the risk owner. These are the individuals formally accountable for managing risks within their sphere of responsibility within the company. And then there are control owners. These are the parties responsible for deploying and maintaining the security controls. These responsibilities are going to fall under existing job titles. So let me give you an example. So in the banking industry, the Chief Risk Officer may be responsible for ensuring that customer data traversing the network is always encrypted, so that sensitive data remains encrypted. They are the risk owner. However, the control owner will be the technical role, say the network administrator, who implements the security control to put that encryption in place. So we have one role owning the risk and another owning the control that mitigates the risk.
Business process owners. So these are generally management-level personnel. They may or may not be technical experts, but they oversee business processes that may rely on IT systems. They're going to make key business decisions that impact use. But as the business process owner, they best understand process-specific operational needs. Now, their duties, their responsibilities might include access management, declaring who and who does not have access, asset control, process leadership, internal audit functions to evaluate the functionality of the business process under new security controls, for example. But they're going to provide a counterbalance to IT security activities to make sure that security is in fact enhancing the business process and not hindering conduction of business.
The steering committee. So this is a group formed within an enterprise. It typically includes senior members of affected groups. It ensures stakeholders impacted by security are considered in the process of implementing controls, and it really functions as a communication channel between the security function and the business.
Now let's take a look at the RACI Matrix. That's R-A-C-I, which represents the four roles of the matrix. There's Responsible, which refers to roles that carry out the actual work involved. There may be multiple people who are responsible in any given RACI matrix. We have Accountable, this is the role with ultimate responsibility for achieving the objective. There's only going to be a single person or entity that's accountable. Consulted, so a consulted person provides subject matter expertise and input that affects the responsibility. So consulted defines who is providing input to the process. And then Informed, these are roles that receive regular status updates but don't provide input, unlike the consulted role. So this is who is receiving information about the process and our progress.
So let's look at some very simple example RACI matrices. So here we have incident response management, where the incident response team is responsible, the CISO is ultimately accountable, the legal department is consulted, and the CEO is informed. Pretty common sense, I think. And I'll provide a few other examples here so you have them for reference as you're studying.
So let's move on and talk about the keys to successful RACI implementation. I'm going to cover five key characteristics. One, we define roles and responsibilities clearly. When we're assigning the RACI, it should be to a role or roles, remembering that multiple parties can be responsible in some cases. It should be a role or roles that generally hold that responsibility in their list of duties, and any exceptions are clearly defined and communicated. Two, we identify key tasks and deliverables. Break the project down into smaller, manageable tasks. Define the specific deliverables expected for each of those tasks. Three, we assign RACI responsibilities. We make sure that each of the four elements of RACI are clearly assigned. We consider skills and expertise. We want to match skills to tasks and allocate responsibilities based on expertise. So we're going to make sure that the R, the A, the C, and the I are defined, and they're matched to the right role or roles within our organization. We communicate and review. We share the completed matrix with the entire team to ensure everyone understands their roles and responsibilities in the RACI matrix. And we treat the RACI matrix as a living document, subject to regular review and update whenever necessary.
I want to give you a tip for the exam, just a key reminder here when it comes to accountability and responsibility. So for the exam, remember that responsibility can be delegated, but accountability cannot. And remember that there may be multiple parties responsible, but only one party will be accountable.
So let's go through a practice question for Section 1A3 so we can apply some of our newly acquired knowledge here. So the question is: Who is responsible for enforcing the organization's information security policies? The security steering committee, the Chief Information Security Officer, the Chief Information Officer, or the Chief Risk Officer? So we have multiple roles here that may be involved. Again, as with most CISM questions, you're going to find that there are multiple plausible answers for any given question, and you need to drill down to the best. So looking here at the options, I can right away cross off the security steering committee because that's going to make recommendations, but it's not going to be ultimately responsible or accountable for any given function. I'm going to cross off the Chief Risk Officer. The Chief Risk Officer, as we discussed earlier, may have purview over information security-related risks, but they're not going to be directly and ultimately responsible for the implementation. There may be some accountability there, but they're not responsible. So that leaves me with the Chief Information Security Officer and the Chief Information Officer. So if I think about direct responsibility here, there's only one option, and that is the Chief Information Security Officer. So when we look at those other C-level roles, they may well be involved in enforcement, but they are not directly responsible. So again, it comes down to making sure you find the best answer given the options, and understanding that the options you're given may not be great options in all cases, but you're trying to drill down to the provably best option amongst the selections you're given.
And I want to give you one final reminder, and I apologize, I'm only doing it because it's so important. It's all about the business. As security leaders, we need to remember the security program must understand and support the business to effectively protect the organization while enabling its business objectives. This ensures that security measures enhance rather than hinder the organization's operations and growth. As you prepare for the exam and take practice quizzes and get ready for exam day, you're going to find that security alignment with business objectives is a common theme throughout the CISM exam. We can't forget it.
And my friends, that's what I have for you for Domain 1, Part A. I hope you're enjoying the series so far. If you have any questions, reach out to me here in the comments or find me on LinkedIn. Happy to help wherever I can. I'll look forward to seeing you in the next installment, which will be Domain One, Part B. And until next time, take care and stay safe.