Information Security Governance
by Krag Brotby · Krag Brotby
Brotby sets out how to build a security program that answers to business objectives rather than to IT, covering strategy development, governance structures, roles, policy hierarchies and metrics. Aimed at managers defining an organization's security posture rather than at engineers.
This link may earn us a small commission at no extra cost to you. Affiliate disclosure
More resources on Cybersecurity Policies
SANS Institute Free Resources
Library of free, customizable information security policy templates maintained by SANS with the Cybersecurity Risk Foundation, spanning acceptable use, passwords, encryption, email and incident response. Gives a starting draft rather than a finished policy.
ISO 27001 Official Site
ISO catalogue entry for ISO/IEC 27001:2022, the certifiable standard for information security management systems. Sets out risk assessment and treatment requirements plus the 93 Annex A controls; the abstract and scope are readable free.
CIS Critical Security Controls
Center for Internet Security's prioritized set of defensive safeguards, grouped into implementation groups so smaller organizations know which controls to adopt first. Free download, with mappings to NIST CSF, ISO 27001 and other frameworks.
NIST SP 800-53
Revision 5 of the federal catalog of security and privacy controls, organized into twenty families spanning access control, incident response, supply chain and more. Practitioners use it to select, tailor and document the safeguards a system or organization must implement.
The Cyberlaw Podcast
Weekly interview and roundup podcast hosted by former NSA general counsel Stewart Baker. Episodes debate current developments in cybersecurity regulation, surveillance, privacy law, AI governance and national security, helping listeners follow how technology policy is argued and made.
nist.gov
NIST.gov is the U.S. government site for standards and guidelines on cybersecurity and information privacy, including risk management, controls, and assessment frameworks. It hosts key publications like the SP 800-series, the NIST Cybersecurity Framework, and related policy resources.