Risk management
How to understand and manage the cyber security risks for your organisation.
Pages
Page 4 of 15
Cyber security governance

What is cyber security governance ?
Cyber security governance is how you control and direct your organisation's approach to cyber security. When done well, it will effectively coordinate the activities of your organisation, when done badly it will lead to poor and delayed cyber security risk decision making. Good cyber security governance enables the flow of cyber security information and decisions around the whole of your organisation.
Just as security is the responsibility of everyone within an organisation, security decision making can happen at all levels. To achieve this, an organisation's senior leadership should use security governance to set out the kinds of security risks they are prepared for staff to take, and those they are not.
What approach to security governance is right for me ?
There is no ‘one size fits all' approach to governance that can work for every organisation. Organisations should establish the security risk management roles and decision making processes that work for them (remembering that some organisations may have to comply with mandated requirements).
Irrespective of any predetermined structures or processes, a good approach to the governance of risk management across an organisation is more likely when:
- the organisations business goals, priorities and appetite for cyber security risk are clear
- the assets that the organisation cares about (or values in terms of achieving its business goals) are clearly identified
- the organisation puts in place the measures needed to make risk management effective
- the organisation understands that for security to be effective, it must be part of ‘business as usual’
- the organisation identifies who is responsible (and accountable) for the security of technology systems and for making decisions about their security (including the on-going security of these systems throughout the whole system life cycle)
- the organisation knows how to acquire the information needed to inform effective and timely cyber security decision making
When organisations are deciding what governance approach is right for them, it may also be helpful to consider:
- how the organisation will manage technology-related security risks, in different business, technology and decision making contexts.
- what external factors are relevant when managing technology-related security risks (e.g. legal, regulatory or sector specific)?
- what business processes are needed to support security risk management decisions?
- what information and documentation is necessary to enable decision makers to make timely, informed and objective security risk management decisions?
- how will the organisation ensure that those responsible for managing risks (and making risk management decisions) have the right business and security skills, knowledge and training?
- how will the organisation provide confidence that its approach to managing risk is effective, and that the systems it uses for business are secure enough to meet its needs?
- how will the organisation ensure traceability and accountability for risk management decisions and actions?
- how will the organisation make continuous improvements to the way it manages security risks?
You should consider the problems that face your organisation and decide upon an approach that is right for you. This is important because adopting a governance process does not, in and of itself, achieve good security. The act of security governance should not be separated from the day-to-day operation and maintenance of good security.
For example, it is not sufficient for senior leadership to simply state that ‘security risks are not acceptable’. Doing so will force those below this level of leadership to take risks based only on their personal knowledge and experience, without fully considering the priorities of your organisation.
What does good cyber security governance look like ?
Invest in risk management, trust decision makers
Governing how risks to technology systems are managed should be no different to the way organisations manage other business activities. The term governance implies that an organisation actively exercises controls over the risks it faces, and provides direction for the security of its business. Effective security governance requires that organisations invest in risk management resources and trust decision makers, so that it has the right people, structures and risk management processes in place. This enables sensible risk management decision making in pursuit of the organisations business goals and objectives.
Delegate decision making
Effective cyber security risk management is built on sensible decision making. However, whilst senior management within an organisation (e.g. the board) remain responsible and accountable for cyber security risk management, they do not necessarily need to make all risk management decisions. Risk management decisions can be made at all levels of an organisation and can be delegated to those people who are best placed to understand the problem. Decision makers should have the right security, business and technical knowledge (together with the skills and experience) to enable them to make timely and effective risk management decisions in different business contexts.
To make security risk management effective, it is important to establish clear lines of communication between those that are accountable and responsible for the security of an organisation, and those who are empowered to make risk management decisions on their behalf. When decision making authority is delegated, the scope of that delegation must be clear. That is, they should understand when decisions need to be escalated for more senior attention within the business.
Deal with complexity and uncertainty
The technology systems used to deliver modern business capabilities can be considered as complex ‘sociotechnical’ systems with interaction between technology, people and business processes. This complexity means that there are times when the causes and effects of security risks can be known and can be managed, and times when they cannot.
Uncertainty in risk management is unavoidable because the information needed by decision makers and practitioners to inform security decisions may not be available, is not known, or is arrived at subjectively. This uncertainty is exacerbated by:
- the biases of those involved in risk analysis, assessment and decision making processes
- limitations in available risk management skills and experience
- limitations in methods and tools, and they way they are used
This complexity and uncertainty does not mean that there is nothing that organisations can do to manage security risks. Rather, those responsible for making decisions need to:
- understand the limitations of the methods, approaches and tools they are using
- understand that there are contexts when risks can be managed through the implementation of predefined security controls and approaches, and contexts when they cannot
- adopt different strategies for making sensible security risk management decisions in different contexts
Develop an effective culture and environment
An effective security culture and environment will also help organisations deal with the unavoidable complexity and uncertainty associated with the systems and services we use and rely on today. An appropriate security culture and environment can be encouraged by:
- ensuring that everyone involved in security risk management decisions understands that achieving the objectives and maintaining the priorities of the business are more important than compliance with generic, predetermined checklists
- employing people who have the cyber security, business and risk management skills, and the knowledge and expertise needed to inform, make, and enable effective decisions
- trusting and empowering those people to make risk management decisions
- minimising the procedural and documentary workload to only that which is necessary to enable timely and effective decision making
- baking risk management into business as usual and design and development lifecycles by for example applying good secure by design principles, so it is viewed as a continuous activity that is consistent with the way other risks are managed (rather than a one-off action)
- making it easy for those responsible for making risk management decisions to have access to (and understand) the information they require
- reducing opportunities for that information to be misinterpreted, diminished, or elaborated in any way that introduces uncertainty and bias
- accepting that technology and security risks will be realised and understanding what the organisation will do to minimise the damage, continue to operate, and make improvements based on lessons learned
- ensuring that communications between those accountable for security, those responsible for making risk management decisions, and those responsible for carrying out risk management activities is clear and meaningful so that information can be correctly and effectively acted upon
Communicate risk management information effectively
The effective communication of risk management information helps organisations to direct and control risk management activities. For this communication to be effective, organisations must establish internal and external channels to communicate with staff, business partners and customers. Communication within an organisation is most effective when it flows amongst the right levels of an organisation: top-down, bottom-up and laterally:
- top-down communication provides corporate direction and business objectives to decision makers
- bottom-up and lateral communication provides detailed technical, non-technical and security information to inform risk management decisions
When communicating internally, this information should as a minimum include:
- business objectives, priorities, and risk management direction
- what the organisation cares about and why
- what risks the organisation will (and will not) take
- who is responsible and accountable for making risk management decisions
When communicating externally with third parties, this information should as a minimum include:
- the risk management and decision-making context
- what needs to be protected and why
- if the security of the protected assets is reliant on another party, then what does the organisation expect that party to do to protect it? (e.g. security terms, procedures or security requirements in contracts)
- where a third party is providing security for something the organisation cares about, how will the organisation gain confidence that the third party is delivering security as expected?
To communicate risk management information in a clear and meaningful way, organisations should use plain English and commonly known business, technology and security terminology. Using bespoke risk management language or specialist terms should be avoided.
It is often assumed that because organisations are using a common risk assessment (or risk management) method, they will be able to use the risk information generated (such as ordinal risk or impact levels or labels) as a short-hand to convey information to risk management decision makers and business partners. Without work to agree the meaning of risk management information, this assumption is incorrect. People and organisations will interpret or misinterpret risk related information based on their individual and group biases, their experience, knowledge and priorities. This is especially true if the risk management information is provided without meaning, explanation or context.
As with any other relationship, trust between parties is built upon good communication that enables each to understand what others value, and to agree the specific meaning of risk management information and risk assessment output. This understanding will enable organisations to trust risk management information provided to them by others, and to use technology systems and services with confidence.
Further reading
Further NCSC reading on controlling and directing cyber security effectively can be seen at Cyber security toolkit for boards.


