In the context of security, what is the primary role of governance?
Choose one.
Governance is how organizational leadership directs and oversees security. Leaders define objectives, approve policies, allocate authority, and assign accountability so security activity aligns with business goals.
Setting direction, establishing policy, and assigning accountability is the definition of governance. Configuring tools, auditing controls, and monitoring logs are all execution or verification activities performed under that governance, not governance itself.
- Ask whether the activity is about deciding and overseeing or about doing the work.
- Governance activities involve leadership decisions such as policy approval and accountability assignment.
- Eliminate the options describing hands-on technical work or audit testing, which are execution and verification tasks.
Exam tip: Governance is leadership setting direction, policy, and accountability; it oversees rather than performing the technical work.
Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.