4
Security Governance
4.1
Introduction
Security governance focuses on all the activities required to manage a functional
area namely information, personnel and physical security. This policy adopts the
US ISO/IEC 27001 Plan-Do-Check-Act (PDCA) continuous improvement model
to structure all security governance processes as illustrated below.
Figure 1 – Security Governance and the PDCA Model
Governance aims to ensure that security programmes support business goals.
Thus, mandatory minimum security governance requirements are as follows: