4 Security Governance 4.1 Introduction Security governance focuses on all the activities required to manage a functional area namely information, personnel and physical security. This policy adopts the US ISO/IEC 27001 Plan-Do-Check-Act (PDCA) continuous improvement model to structure all security governance processes as illustrated below. Figure 1 – Security Governance and the PDCA Model Governance aims to ensure that security programmes support business goals. Thus, mandatory minimum security governance requirements are as follows:

Select target paragraph3