Governance as the Integration Layer: Uniting Enterprise Risk Management and Cybersecurity for the Cloud and IoT Era
Description
Volume 6 of 10 in the Engineering-to-Research Monograph Series. Cybersecurity is still too often run as a technical silo bolted onto an organization rather than woven into how it understands and prices risk, and that separation is the root cause of the most consequential failures: risks that fall between the business and the security team, controls that satisfy an audit but not a threat, and recovery plans that exist only on paper. This report argues that governance is the integration layer that dissolves the silo: the mechanism by which cyber risk becomes enterprise risk and enterprise strategy becomes technical control. It builds the argument in four layers, from the enterprise-risk portfolio view, through governance (the NIST Cybersecurity Framework 2.0 Govern function and NIST IR 8286), down to technical control (a hybrid role-and-attribute access model and Zero Trust) and a governed resilience layer. It contributes a layered governance-to-control reference model and two design principles, and shows the chain holds across cloud and IoT because enforcement is decoupled from infrastructure.
The paper and figures are licensed CC BY 4.0. This work contains no confidential or proprietary employer information.
Files
05_Monograph_6_ERM_and_Cybersecurity_Governance.pdf
Files
(466.5 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:2b797bcf363adf0ba287095fe6219780
|
169.9 kB | Download |
|
md5:c21fa96d640e892a564ef0ef7b17ef8a
|
296.6 kB | Preview Download |
Additional details
Software
- Repository URL
- https://github.com/AlanP13/Governance-as-the-Integration-Layer-Vol6
- Development Status
- Active