v3.4.0 — Security Governance & Executive Leadership
What's New
Domain 17: Security Governance & Executive Leadership — the strategic governance layer for the cybersecurity-pro skill, covering the "why" and "who decides" at board and C-suite level.
New Reference File
references/security-governance-executive.md (797 lines, 9 sections):
| Section | Content |
|---|---|
| 1. Governance Landscape & Role Architecture | Hierarchy diagram, governance vs management distinction |
| 2. NIST CSF 2.0 GOVERN Function | 6 categories (GV.OC/RM/RR/PO/OV/SC), 31 subcategories |
| 3. ISO 27014:2020 Governance | 5 processes (Evaluate/Direct/Monitor/Communicate/Assure) |
| 4. Security Maturity Models | C2M2 v2.1 (10 domains, MIL 0-3), CMMI, self-assessment |
| 5. Executive Roles: CISO, CAIO, CAISO | Role definitions, reporting structures, decision tree |
| 6. Board Reporting & SEC Disclosure | SEC 8-K/S-K rules, materiality template, KPI dashboard |
| 7. AI Governance at Executive Level | NIST AI RMF GOVERN, ISO 42001, EU AI Act obligations |
| 8. Implementation Roadmap | 5-phase (Month 1-12), KPIs, operating model diagram |
| 9. Framework References & Checklist | 10-framework table, Quick Win/Standard/Advanced checklist |
Key Frameworks
- Primary: NIST CSF 2.0 GOVERN, ISO/IEC 27014:2020
- Supporting: NACD Handbook 2023, C2M2 v2.1, SEC Disclosure Rules 2023, NIST AI RMF 1.0, ISO 42001:2023, EU AI Act, Singapore IMDA, CMMI
Changes
- 15 files changed (1 new + 14 modified), 999 insertions
- SKILL.md: 17 domains with full keyword set and decision tree
- Cross-references backfilled in D4, D8, D9, D12, D16
- D16 updated: GOVERN mapping table includes D17, dependency diagram with GOVERN box
- docs/INSTALL.md: updated version refs and file lists to 17
- QA fixes: subcategory count (31 not 32), SEC URL, CISO keyword precision
- Validation: 55 PASS, 0 FAIL