Security+Program management
Governance and compliance
Governance is internal direction. Compliance is meeting a stated requirement. Policies, standards, and procedures sit at different altitudes.
14 min read
Objectives
- Order policy, standard, procedure, and guideline from broad to specific
- Separate governance, compliance, and security outcomes
- Name why scope and authorization are governance issues for a tester
On this page
Core idea
Governance is how the organization directs and controls security: who decides, what must be true, and how exceptions work. Compliance is evidence that you meet a requirement from a law, a contract, or your own policy. A control can serve both. A password rule might exist because a standard demands it and because it reduces a risk. If it only exists to satisfy an auditor and it does not fit the risk, say that honestly. The exam sometimes wants the compliance answer anyway, because that is what the stem named.
Altitude of documents:
| Document | What it does |
|---|---|
| Policy | States management intent. “Customer data is encrypted at rest.” |
| Standard | Sets the mandatory specification. “Use these approved algorithms.” |
| Procedure | Says the steps people follow. |
| Guideline | Recommends. It is not mandatory. |
Exceptions belong in the governance process: a named approver, a reason, a compensating control, and an expiry. An exception that never expires is a quiet policy change.
Due care is doing what a reasonable organization would do. Due diligence is the investigation before a decision, such as looking at a vendor before you sign. The exam uses both. Diligence is the homework. Care is the ongoing conduct.
For a tester, written authorization and a defined scope are governance. The ethics note on the BSCP track is the personal version. On this exam, testing without permission is not a gray area. It is outside the policy and often outside the law. You do not need statute numbers to answer “get written permission and stay in scope.”
Exam lens
A stem that quotes mandatory language is a policy or a standard, depending on whether it is intent or a specific rule. A stem that says “recommended” is a guideline. A stem about meeting a regulation is compliance. A stem about who may accept an exception is governance. Pick the altitude they described.
Common pitfalls
Writing a procedure when they asked for a policy. Calling every legal topic “compliance” when the question was about due diligence before a merger. Treating a passed audit as proof the program is governed. The audit checked what it checked. Assuming guidelines are enforceable. They are not, unless a policy says they are.