Governance, Risk & Compliance
Security Governance & Operating Model Design
Decide who decides. Then make the decisions visible.
The situation
What the client receives
Schedule of deliverables
- Target security operating model and organisation design
- Policy architecture and full policy set
- Security committee charter, cadence and decision rights
- RACI across security, IT, legal, procurement and business
- Security KPI / KRI framework and executive dashboard
- Maturity assessment and multi-year improvement roadmap
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- NIST CSF 2.0 (Govern function)
- COBIT 2019
- CGEIT practice
- ISO/IEC 27001 Cl. 5
Related services
Discuss this engagement
Tell us about how security decisions are taken today and where they stall and we will set out the scope, the method and the reporting format.