Governance, Risk & Compliance

Security Governance & Operating Model Design

Decide who decides. Then make the decisions visible.

The situation

Organisations rarely fail on technology alone; they fail because nobody owns the decision.

We design the security operating model — the committee that meets, the RACI that holds, the policy hierarchy that people can actually follow, the metrics that reach the board and the assurance cycle that keeps it honest. Drawn directly from designing and running exactly this at directorate scale inside the European Commission.

What the client receives

Schedule of deliverables

  1. 01Target security operating model and organisation design
  2. 02Policy architecture and full policy set
  3. 03Security committee charter, cadence and decision rights
  4. 04RACI across security, IT, legal, procurement and business
  5. 05Security KPI / KRI framework and executive dashboard
  6. 06Maturity assessment and multi-year improvement roadmap

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • NIST CSF 2.0 (Govern function)
  • COBIT 2019
  • CGEIT practice
  • ISO/IEC 27001 Cl. 5

Discuss this engagement

Tell us about how security decisions are taken today and where they stall and we will set out the scope, the method and the reporting format.

Contact us