Tyscorpa Study resources Open the Academy

Security Governance

Policies, procedures, standards, guidelines, and major security frameworks.

SY0-701 Obj. 5.1 Security Program Management 20% of the exam

Governance Document Hierarchy

DocumentDescriptionMandatory?Level of Detail
PolicyHigh-level statement of intent and management direction. Sets "what must be done."YesLow (general)
StandardSpecific requirements that support a policy. Defines "how exactly" something must be done.YesHigh (specific)
ProcedureStep-by-step instructions for completing a specific task.YesHighest (step-by-step)
GuidelineRecommended best practices. Not mandatory — advisory only.No (advisory)Varies
BaselineMinimum security configuration for a system type.YesSystem-specific

Common Security Policies

Major Security Frameworks

FrameworkPurposeWho Uses It
NIST CSF (Cybersecurity Framework)Risk-based framework: Identify, Protect, Detect, Respond, RecoverAll industries (US); voluntary but widely adopted
NIST SP 800-53Comprehensive security control catalogUS federal agencies; contractors
ISO/IEC 27001International standard for Information Security Management Systems (ISMS)Global organizations; certifiable
ISO/IEC 27002Code of practice / guidelines for implementing ISO 27001 controlsCompanion to 27001
SOC 2AICPA audit standard for service organizations covering Trust Service Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy)SaaS/cloud service providers
PCI DSSPayment Card Industry Data Security Standard — 12 requirements for handling cardholder dataAny org handling credit/debit cards
HIPAA Security RuleRequirements for protecting ePHI (electronic Protected Health Information)US healthcare providers, insurers, business associates
CIS Controls18 prioritized security controls (formerly top 20)Organizations of all sizes; free
MITRE ATT&CKKnowledge base of adversary TTPs; used for threat modeling and detection gap analysisSOC teams, threat hunters, red teams

Legal Environment

Governance Structures

Exam Tip: Know the hierarchy: Policy (mandatory, high-level) → Standard (mandatory, specific) → Procedure (step-by-step) → Guideline (advisory). Framework questions: NIST CSF = voluntary; ISO 27001 = certifiable; PCI DSS = payment cards; HIPAA = healthcare. SOC 2 = service providers.

External Resources

NextRisk Management

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy