Organizational Governance Processes
Organizational governance includes strategic planning, risk management, compliance, performance monitoring, and decisionmaking processes to ensure accountability and alignment with goals.
6 slides · 3 min read · Domain 1
Governance is the process of running an organization. It is the process that defines how decisions are being made, by whom, and how they are implemented throughout the organization. Governance varies by organization. A small private business | might have a simplistic process in which all decisions are made by the business owner, whereas in a large corporation, decisions are made by the business owner, board of directors, and other stakeholders based on regulations, legislative requirements, or other guidelines.
Each organization has its own process for making decisions, based on its structure, goals, nature, and industry.
Some companies make use of a governance committee to determine how decisions are made within the organization. Governance committees are required for most nonprofit organizations; the governance committee recruits and selects board members and determines whether the board and individual members are performing optimally.
Organizational governance processes are often defined by laws and regulations that apply in the jurisdictions the organization operates in, has interests or assets in, or does business with entities within.
Depending on the industry or nature of the organization and the jurisdictions involved, these laws and regulations can impose stringent standards for the internal "minding of one's own business" and the ways that organizational governance itself is carried out, monitored, and managed. These may flow directly into information security functions related to the misuse of inside information, privacy, and other data protection needs and safety.
The following business decisions might
The goal of security is affect the organization's security:
to enhance and support
- Acquisition. If the organization decides
business goals, and just
to purchase another business unit, the as security decisions security implications can be extensive. New legislations and regulations imposed can affect business on the acquired business may now affect goals, organizational the parent company. Current policies and practices that may differ between the decisions can affect entities and need to be merged. Security vulnerabilities may be introduced to the security.
corporate network.
- Merger. Much like acquisitions, a merger of two organizations entails aligning the security governance of the resulting entity.
- Divestiture. When an organization decides to sell off or cede operations for a subsidiary or business process, it is vital to assess what property exists and requires security control and whether to include data. These merger and acquisition (M&A) risks often involve the gaining organization inheriting the legacy systems, policies, procedures, and data of the business being acquired or merged. Oftentimes, these acquired organizations did not practice effective information systems security, systems configuration management, or other reasonable and prudent information risk reduction measures.
The decision to acquire and merge is often made at the highest levels of both organizations, and it usually does not involve a detailed assessment of assets and risks.
The Marriott group
Text on this slide
A case in point is Marriott Hotel's problems in 2018 and 2020 with information systems
did not practice (or
vulnerabilities they had inherited through M&As. In late 2018, the hotel chain
was not provided
announced it had suffered a major data
the opportunity to
breach that included hundreds of millions of customer records including credit card
perform) proper due
numbers, passport numbers, and personal
diligence with respect
data. The breach affected one of the reservation systems used by the Starwood
to the information
brands, which included Westin, Sheraton, St.
security functions of
Regis, and W hotels. The Starwood network had been compromised sometime in 2014
the companies being
before its acquisition by Marriott in 2016. However, Marriott is the brand that suffered acquired.
a reputation hit from the incident. These
They did not conduct a full information risks are associated with the acquisition security risk assessment and thus had of a company, though the conclusions and little reason to believe that the Starwood takeaways are relevant for any organization.
network, its systems, and databases were secured in compliance with the risk posture Marriott defines.
