isaca.org
Unknown
ISACA is a global professional association focused on information governance, cybersecurity, risk management, and IT audit. It provides guidance, frameworks (notably COBIT), research, and training, plus certifications like CISA, CISM, and CGEIT to support cybersecurity governance and IT assurance.
More resources on Cybersecurity Governance
nist.gov/cyberframework
Official NIST Cybersecurity Framework hub explaining the CSF and how to use it for risk-based cybersecurity programs. It provides the framework core (Identify, Protect, Detect, Respond, Recover), implementation guidance, profiles, mappings to other standards, and downloadable resources.
SANS Institute Governance Papers
A searchable library of free SANS Institute white papers on cybersecurity governance topics such as policy development, risk management, and compliance frameworks, written by practitioners and reviewed through the SANS Reading Room submission process.
ISACA Cybersecurity Resources
ISACA's hub for cybersecurity governance resources, including white papers, the annual State of Cybersecurity workforce survey, training courses, and certification guidance for audit, risk, and information security professionals.
CISO Series Podcast
Discussions, tips, and debates from security practitioners and vendors on how to work better together to improve security for themselves and everyone else.
Cybersecurity Program Development for Business
Chris Moschovitis, a cybersecurity consultant, walks business executives through building a cybersecurity program from risk assessment to governance roles and responsibilities, using plain language and case studies. Readers learn to evaluate organizational risk and make practical mitigation decisions.
Identity Protection and Governance
Second course in Microsoft's AZ-500 exam preparation series, covering Azure AD Identity Protection, Conditional Access, multifactor authentication, Privileged Identity Management, role-based access control, Azure Policy and resource locks. Learners finish able to secure and govern identities and access in Azure subscriptions.