A global retail company is establishing an information security governance framework. The CISO wants to ensure that the framework effectively supports business objectives while managing risk. Which TWO of the following are essential components of an effective security governance framework? (Choose two.)
Clearly defining security roles and responsibilities is essential for accountability and effective governance. It ensures that every aspect of the security program has an owner, preventing gaps and overlaps. This clarity also enables better communication and coordination between business units and the security team, aligning security activities with business goals.
Why this answer
An effective security governance framework must include clear roles and responsibilities to ensure accountability, and a process for regularly updating policies to adapt to changes. These components provide the structure and adaptability needed to align security with business objectives and manage risk. Advanced technologies, centralized decision-making, and operational centers are not core governance elements; they are tactical or operational considerations that support the framework.
Exam trap
The trap here is equating governance with operational capabilities or technologies, rather than focusing on the structural and process elements that define oversight and accountability.