Compact
true
Responsibilitiy Area: Security Implementation Technology/Specialization: Security Implementation Technology
Engaged in NEC's security proposal and implementation promotion through developing OS/middleware fortification tools, conducting risk assessments, and supporting security requirement definition and design. Currently primarily responsible for establishing regulations and guidelines for security implementation. Holds CISSP, CISA, and Information Security Support Specialist (RISS) certifications.Hobbies include weekend yoga and occasional handmade crafts (making plum wine, plum syrup, miso, jam, etc.)—a mother engineer.

※日本語版はこちら(For the Japanese version, please refer to here.)

Security governance is a key element for determining an organization's overall security policies and strategies and reducing risks. This blog introduces practices and tips for security departments to implement secure development, based on the framework and objectives of security governance defined in ISO/IEC 27014 (Information Security Governance), with examples from NEC.

What is Security Governance?

The environment surrounding security is becoming increasingly complex year by year, with factors such as the increasing sophistication of cyberattacks, the strengthening of laws and regulations, and the growing visibility of supply chain risks. Under these circumstances, the importance of security governance—establishing organization-wide security policies and strategies to reduce risks—is growing significantly.
According to ISO/IEC 27014 (Governance of Information Security), “security governance” can be understood as the process by which an organization establishes security objectives and strategies aligned with its operational goals and strategy, implements activities based on these, and continuously evaluates and analyzes them. (Note: While ISO/IEC 27014 terms it “Information Security Governance,” as it is applicable beyond information security, it is simply referred to as “Security Governance” in this blog.) The primary purpose is for senior management to lead in defining the strategic direction for security and to work toward its realization across the entire organization.
On the other hand, there is a similar term “security management” which refers to the execution at operational teams within the framework of security governance. An Information Security Management System (ISMS) based on ISO/IEC 27001 is a management system designed to maintain confidentiality, integrity, and availability of information assets. It consists of a continuous process based on the PDCA cycle, including risk assessment, implementation of countermeasures, operation, and improvement.

Considering security governance and security management in terms of objectives, subject, and expected results, the differences are as follows. (Compiled by the author based on ISO/IEC 27001 and ISO/IEC 27014)

Item
1
1
Security Governance
1
2
Column3
1
1
Security Management
1
2
Column5
1
1
Objective
1
1
  • Align business objectives and strategies with security objectives and strategies
  • Provide value to management and stakeholders
  • Ensure security risks are appropriately addressed and fulfill accountabilities
1
2
Column3
1
1
  • Systematically manage risks and pursue continuous improvement to ensure security
1
2
Column5
1
1
Subject
1
1
Management and Administrative Departments
1
2
Column3
1
1
Operational Departments (Managers/Employees)
1
2
Column5
1
1
Expected Results
1
1
  • Understand the security situation and enable swift decision-making regarding risks
  • Achieve efficient and effective investment in security
  • Ensure compliance with laws, regulations, and contracts
1
2
Column3
1
1
  • Ensures confidentiality, integrity, and availability for protected assets
  • Provides stakeholders with assurance that security risks are appropriately managed
1
2
Column5
1
1

Also, the relationship between security governance and security management is as shown in Figure 1. Governance determines “what to protect and to what extent,” while management implements “how to protect it.”

Figure1: Security Governance Model (created by the author based on ISO/IEC 27014)
Figure1: Security Governance Model (created by the author based on ISO/IEC 27014)
50

The Relationship between Secure Development and Security Governance

NEC's secure development practices for products, systems, and services are based on the Security by Design [1] concept, defined by the former Cabinet Cyber Security Center (now the National Cyber Coordination Office) as “measures to ensure information security from the planning and design stages.” This approach considers security from the planning and design stages to minimize backtracking and reduce costs.
Security governance is essential to ensure secure development is practiced effectively in operational teams, rather than relying on an ad hoc approach dependent on individual engineers' efforts. NEC has established its Cybersecurity Management Regulations as a company-wide policy effective from 2023 to define secure development structures and processes within each organization, serving as an expression of its security governance strategy and policies.

Establishing the Structures and Processes Supporting Secure Development Governance

In this chapter, we explain how NEC practices secure development governance, referencing the security governance model outlined in ISO/IEC 27014.

Processes Necessary for Practicing Security Governance

ISO/IEC 27014 lists the following five processes as necessary for practicing security governance.

Process
1
1
Explanation (summarized by the author)
1
4
Column3
1
1
Column4
1
1
Column5
1
1
Evaluate
1
1
Management considers the current status and future projections regarding security objectives and strategies, and makes necessary adjustments to optimize their achievement going forward.
1
4
Column3
1
1
Column4
1
1
Column5
1
1
Direct
1
1
Management presents the company's security objectives and strategy to administrators and employees
1
4
Column3
1
1
Column4
1
1
Column5
1
1
Monitor
1
1
Management visualizes and monitors the status of governance activities to assess the achievement of security objectives and strategy
1
4
Column3
1
1
Column4
1
1
Column5
1
1
Communicate
1
1
Management and external stakeholders exchange security-related information necessary for both parties
1
4
Column3
1
1
Column4
1
1
Column5
1
1
Assure
1
1
Management outsources independent, objective audits, reviews, and certifications to external parties
1
4
Column3
1
1
Column4
1
1
Column5
1
1

These are processes implemented by management, but since it is difficult for management to conduct them on their own, many companies likely have a security department that creates the foundation for executing these processes and serves as a bridge between management and operational teams managers and employees. As shown in Figure 1, the security department primarily handles the “Direct” and “Monitor” aspects.
Regarding these two processes, NEC's security department breaks them down and implements them as follows:

Practicing Security Governance in NEC's Secure Development

In NEC's secure development, the Security Department practices security governance and supports security management in the operational environment through measures such as the following.

For more information, including the above content, please refer to NEC's “Cybersecurity Management Report” [2], which summarizes our activities related to security governance and secure development.

Key Points for Designing and Operating Policies and Standards

ISO/IEC 27014 defines the following six objectives for security governance. These are also useful for designing and operating policies and standards. Below is a summary of the six objectives based on my understanding.

Given the points above, I believe the following are key tips for enhancing the effectiveness of security governance from the perspective of the security department.

There are still many aspects we need to improve and many things we must address going forward, but I have summarized the key points by looking back on our progress as of this point.

Summary

I believe security governance in secure development is a structure for the entire organization to “think, execute, and improve” security. The security department, guided by executive leadership, establishes the frameworks and standards that enable operational teams to implement security practices. They are responsible for continuously supporting and improving these efforts. Security is not just about “protecting” – it can become a strategic element for “building trust.” Being in the position of establishing the foundational policies and standards for this is truly a sobering responsibility. I sincerely hope this article provides some useful insights to others in similar roles.

References

[1]情報セキュリティを企画・設計段階から確保するための方策 (SBD(Security by Design))
https://www.nisc.go.jp/pdf/policy/general/SBD_overview.pdf
[2]サイバーセキュリティ経営報告書2025
https://jpn.nec.com/sustainability/ja/security/index.html
[3]サイバーセキュリティ経営ガイドライン
https://www.meti.go.jp/policy/netsecurity/mng_guide.html

Profile

alt
original
50

Atsuko Imose, CISSP, RISS
Responsibilitiy Area: Security Implementation Technology
Specialization: Security Implementation Technology

Engaged in NEC's security proposal and implementation promotion through developing OS/middleware fortification tools, conducting risk assessments, and supporting security requirement definition and design. Currently primarily responsible for establishing regulations and guidelines for security implementation. Holds CISSP, CISA, and Information Security Support Specialist (RISS) certifications.
Hobbies include weekend yoga and occasional handmade crafts (making plum wine, plum syrup, miso, jam, etc.)—a mother engineer.