Exam objective
SY0-701 5.1: Security Governance
Security Governance for Security+
This Security+ topic covers governance document hierarchy and examples: guidelines, policies, standards, and procedures; Named policy examples: acceptable use policy (AUP), information security policies, business continuity, disaster recovery, incident response, software development lifecycle (SDLC), and change management; Named standard examples: password, access control, physical security, and encryption standards; Named procedure examples: change management, onboarding, offboarding, and playbooks.
Start first lesson4 lessons in this topic
Common mistakes to avoid
Learners often mix up policy, standard, and procedure. The shortest correction is: policy says what must be true, standard says the required measurable baseline, and procedure says how to do the work.
Learners often treat regulatory and legal as identical. The correction: regulatory usually points to a regulator or formal regulation; legal is broader and includes contracts, lawsuits, court orders, liability, and counsel-driven obligations.
Learners often equate centralized with more secure and decentralized with less secure. The correction: both are governance models with tradeoffs. Centralized improves consistency; decentralized improves local responsiveness.
Learners often assume the administrator is the owner because the administrator has technical access. The correction: the owner is accountable for business and risk decisions; the custodian administers or safeguards the asset.