What's changed: Initial version
4.4Management and Security Governance
Learn information security governance led by management, corporate governance that disciplines the enterprise as a whole and the internal control that forms part of it, the Cybersecurity Management Guidelines that push executives toward security investment, and how supplier management fits within security governance.
Earlier chapters focused mainly on frontline controls; this section raises the vantage point to cover how executives take responsibility for and govern security. As a capstone to SG, understand how individual controls connect to management-level decision-making.
4.4.1Information security governance and corporate governance
- Information security governance is a mechanism, led by management, that makes policy decisions, resource allocation, and monitoring for information security function across the whole organization. Its core is that management itself recognizes the risk and bears accountability, rather than leaving it to the front line. Where the ISMS (Chapter 2) is the mechanism for "how to operate," governance is the higher-level view that management is responsible for making that mechanism function.
- Corporate governance is the mechanism by which shareholders, the board of directors, and others oversee management's conduct of the business and ensure transparency and soundness. Information security governance is positioned as part of corporate governance—its concretization in the IT/security domain. Internal control (section 2 of this chapter) is the mechanism management establishes and operates to ensure proper business conduct, and it is one component supporting corporate governance.
4.4.2Cybersecurity Management Guidelines and supplier management
- The Cybersecurity Management Guidelines, formulated by the Ministry of Economy, Trade and Industry and IPA, is guidance for executives to exercise leadership in advancing cybersecurity measures. It consists of "three principles executives should recognize" and "ten important items for implementing security measures," and is distinguished by prompting executives to shift their mindset toward viewing cybersecurity as a management investment rather than a cost (expense).
- Supplier management reflects the view that a company's own security measures are not enough—executives must also grasp and control risk across the entire supply chain, including outsourcing partners and cloud providers. The Cybersecurity Management Guidelines' ten important items explicitly call for risk management covering the entire supply chain, and matters such as supplier selection criteria, quality assurance via an SLA, and periodic audits are things executives should be responsible for as part of information security governance.
The staples: information security governance is led by management, which bears accountability; information security governance is part of corporate governance; the Cybersecurity Management Guidelines comprise three principles plus ten important items, framing cybersecurity as a management investment rather than a cost; and risk management across suppliers and the entire supply chain falls within executives' scope of responsibility. Keep in mind the difference in who leads—management versus the front line.
Consider a discussion at the board of mid-size logistics company F to see how management and security governance connect. One year, the IT department reported to the board after the fact that "a minor incident occurred at an outsourced IT vendor but was already handled by our department," prompting an outside director to ask, "why wasn't this recognized and deliberated by the management committee beforehand?" That question exposed a gap in information security governance—the principle that management itself must recognize the risk and bear accountability rather than leaving security response entirely to the front line. Taking this as an opportunity, F's board revisited the "three principles executives should recognize" from the Cybersecurity Management Guidelines (1. executives must recognize cybersecurity risk as one type of management risk and drive countermeasures; 2. security measures are needed not only for the company itself but across the supply chain including suppliers; 3. ongoing communication with stakeholders is needed even in normal times), and shifted policy to budget for cybersecurity measures as a management investment rather than merely an IT department expense. In parallel, to address "risk management across the entire supply chain" from the ten important items, F overhauled its supplier management mechanism, requiring its SLAs with key suppliers to specify an obligation and deadline for reporting security incidents, and adding submission of an annual third-party audit result as a contract requirement. This whole effort was an attempt to clearly reposition information security governance within existing frameworks—internal control (approval and monitoring of business processes) and corporate governance (the board's oversight of management)—achieving management-level prevention of recurrence that a one-off technical fix alone could not deliver.
| Concept | Who leads | Positioning |
|---|---|---|
| Corporate governance | Shareholders/board | Oversight and transparency of management as a whole |
| Information security governance | Executives | Part of corporate governance in the IT/security domain |
| Internal control | Established/operated by management | A component supporting corporate governance |
| Cybersecurity Management Guidelines | Formulated by METI/IPA | Three principles plus ten items promoting security as an investment |
Trap: "information security governance just needs to be led by the IT department, and executives need not be involved" is wrong. The core of governance is that management itself recognizes the risk and bears accountability—leaving it to the front line contradicts the point of this section. Also, "cybersecurity measures are a cost, and return on investment should not be expected" is wrong—the Cybersecurity Management Guidelines promote the mindset of viewing it as a management investment. Furthermore, "a supplier's security measures are the supplier's own responsibility, and the outsourcing party need not be concerned" is wrong—risk management across the entire supply chain falls within the outsourcing party's (executives') scope of responsibility.
4.4.3Section summary
- Information security governance is the mechanism, led by management, making policy, resource allocation, and monitoring function. It is part of corporate governance
- The Cybersecurity Management Guidelines comprise three principles plus ten important items, promoting a shift to viewing security as a management investment
- Supplier management, as risk management across the entire supply chain, falls within executives' scope of responsibility
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which mechanism has the board itself, rather than leaving it to the front line, get involved in and bear accountability for information security policy decisions, resource allocation, and monitoring?
Q2. Which is the most accurate characterization of the guidance, formulated by the Ministry of Economy, Trade and Industry and IPA, for executives to exercise leadership in advancing cybersecurity measures?
Q3. Which initiative is most consistent with the view that executives should grasp and control risk across the entire supply chain, including outsourcing partners and cloud providers, not just the company's own security measures?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

