Skip to content
Jon MarienStudy Desk

Security+Program management

Security program management

Domain overview. This domain is who decides, which risks are accepted, and how outsiders and auditors fit.

12 min read

Objectives

  • Separate governance from the technical control that implements it
  • Point to risk, compliance, third parties, awareness, and audits
  • Recognize a management answer on a technical stem
On this page
  1. Core idea
  2. Exam lens
  3. Common pitfalls

Core idea

Program management is the system around the technicians. Published SY0-701 weight is about a fifth of the exam. The questions feel soft until you notice they have precise terms.

The pieces:

  • Governance sets direction, roles, and policy. Compliance is whether you meet an external or internal requirement. They share a note because the exam pairs them.
  • Risk management is how you choose what to do about uncertainty. Its own note, and the one to slow down on.
  • Third-party risk is the same risk idea pointed at vendors and partners.
  • Awareness is the outline on training. It is a control, and it is also a program with an owner.
  • Audits and assessments are how someone independent checks the story. Outline for now.

A policy without an owner, a review date, and a control that implements it is a document. The exam still expects you to know that the policy is the managerial control and the firewall rule is the technical one. Both can be the right answer to different stems.

Security’s job inside the program is to inform the decision. Accepting risk is a business decision made by someone with authority, not a mood the security team is in.

Exam lens

If the stem asks who is accountable, or what document requires a behavior, stay in this domain. If it asks which packet to drop, leave. When a technical person “just lives with” a critical finding, the missing piece is often a formal risk acceptance, not another scanner.

Common pitfalls

Writing policies as if they were configurations. Ignoring this domain because it is not hands-on. BSCP will not teach it, and Security+ will ask it. Treating compliance as the same thing as security. You can pass an audit and still be fragile. You can be sensible and still fail an audit. Say which one the stem asked about.

More on this track