02 — Capability · BC-760.10
Security Governance & Risk
Set the security policies and control framework, assess where the real risks are and prove to leadership and auditors that the controls that matter are in place and working.
- Security GRC
- Security Risk Management
- Security Assurance
In scope
- Security policy and standards
- Security risk assessment and treatment
- Control testing and audit support
- Security awareness and training content
Out of scope
- IT policy framework beyond security (see BC-710)
- Internal audit independence and planning (see BC-160)
Realized by · 0
- No product in the catalog yet.
Used in · 0
- Not yet placed on a value stream.
Build it · 1
Decomposes into · 4
- BC-760.10.10Security Policy & StandardsPublish the security rules and the technical standards that implement them, scoped so every team can tell which apply to its work.
- BC-760.10.20Security Risk AssessmentIdentify threats and weaknesses against the assets that matter, rate the risk and decide whether to treat, accept or transfer it.
- BC-760.10.30Control AssuranceTest that security controls operate as designed, on a schedule, and keep the evidence auditors and customers ask for.
- BC-760.10.40Security AwarenessTeach the workforce what attacks look like and what to do, and measure whether the behavior actually changed.