Skip to content
Blueprint Catalog

    ↑↓ move · Enter open · Esc close

    02 — Capability · BC-760.10

    Security Governance & Risk

    Set the security policies and control framework, assess where the real risks are and prove to leadership and auditors that the controls that matter are in place and working.

    • Security GRC
    • Security Risk Management
    • Security Assurance

    In scope

    • Security policy and standards
    • Security risk assessment and treatment
    • Control testing and audit support
    • Security awareness and training content

    Out of scope

    • IT policy framework beyond security (see BC-710)
    • Internal audit independence and planning (see BC-160)

    Realized by · 0

    • No product in the catalog yet.

    Used in · 0

    • Not yet placed on a value stream.

    Build it · 1

    Decomposes into · 4