Why Governance and Policy Matter
Technology alone cannot secure an organization. Systems need rules, responsibilities, and decision-making structures. That is the role of security governance.
Governance answers questions such as:
- Who approves security policies?
- Who owns which assets?
- What controls are mandatory?
- How are exceptions handled?
- How are incidents reported?
- How is compliance checked?
A policy is a formal statement of expectations and rules. A standard gives required specifications. A procedure gives step-by-step instructions. A guideline gives recommended practice.
Example:
- Policy: all sensitive data must be protected
- Standard: passwords must meet minimum requirements
- Procedure: how new accounts are requested and approved
- Guideline: tips for secure remote work
Core Security Policies Students Should Recognize
Introductory security courses commonly discuss policies such as:
- acceptable use policy,
- password policy,
- access control policy,
- backup and recovery policy,
- incident reporting policy,
- remote access policy,
- email and internet use policy,
- data classification and retention policy.
A good policy is clear, enforceable, aligned to business needs, and supported by management. A policy that nobody follows is not effective governance.
Security governance also links to awareness training. Many incidents involve human error, phishing, weak handling of data, or policy violations. This is why awareness is not optional.
Ethics, Professional Responsibility, and User Trust
ProReviewer — locked
Drills, code labs, and full solutions.
Philippine Legal and Regulatory Context
ProReviewer — locked
Drills, code labs, and full solutions.
Practice & Exam Drills — Lesson 7
ProReviewer — locked
Drills, code labs, and full solutions.