Skip to content

v3.4.0 — Security Governance & Executive Leadership

Choose a tag to compare

@pitimon pitimon released this 22 Feb 01:08
· 41 commits to main since this release

What's New

Domain 17: Security Governance & Executive Leadership — the strategic governance layer for the cybersecurity-pro skill, covering the "why" and "who decides" at board and C-suite level.

New Reference File

references/security-governance-executive.md (797 lines, 9 sections):

Section Content
1. Governance Landscape & Role Architecture Hierarchy diagram, governance vs management distinction
2. NIST CSF 2.0 GOVERN Function 6 categories (GV.OC/RM/RR/PO/OV/SC), 31 subcategories
3. ISO 27014:2020 Governance 5 processes (Evaluate/Direct/Monitor/Communicate/Assure)
4. Security Maturity Models C2M2 v2.1 (10 domains, MIL 0-3), CMMI, self-assessment
5. Executive Roles: CISO, CAIO, CAISO Role definitions, reporting structures, decision tree
6. Board Reporting & SEC Disclosure SEC 8-K/S-K rules, materiality template, KPI dashboard
7. AI Governance at Executive Level NIST AI RMF GOVERN, ISO 42001, EU AI Act obligations
8. Implementation Roadmap 5-phase (Month 1-12), KPIs, operating model diagram
9. Framework References & Checklist 10-framework table, Quick Win/Standard/Advanced checklist

Key Frameworks

  • Primary: NIST CSF 2.0 GOVERN, ISO/IEC 27014:2020
  • Supporting: NACD Handbook 2023, C2M2 v2.1, SEC Disclosure Rules 2023, NIST AI RMF 1.0, ISO 42001:2023, EU AI Act, Singapore IMDA, CMMI

Changes

  • 15 files changed (1 new + 14 modified), 999 insertions
  • SKILL.md: 17 domains with full keyword set and decision tree
  • Cross-references backfilled in D4, D8, D9, D12, D16
  • D16 updated: GOVERN mapping table includes D17, dependency diagram with GOVERN box
  • docs/INSTALL.md: updated version refs and file lists to 17
  • QA fixes: subcategory count (31 not 32), SEC URL, CISO keyword precision
  • Validation: 55 PASS, 0 FAIL

Full Changelog

v3.3.1...v3.4.0