Security Steering Committee
Definition
A cross-functional management body, typically chaired by the CISO or Chief Risk Officer, that coordinates security priorities across business units, approves major initiatives, and ensures business lines take ownership of risks allocated to them.
- Chair
- Typically CISO or Chief Risk Officer
- Composition
- Cross-functional, spanning business units
- Role
- Coordinates priorities and approves major initiatives
Common questions
How is a security steering committee different from a security governance framework in general?+
The committee is one specific governance mechanism, a recurring body of people making decisions; governance is the broader set of policies, roles and accountability structures the committee operates within.
Why does the committee include business-unit representatives rather than just security staff?+
Business lines own the risks that security controls are meant to mitigate, so their presence is meant to ensure they take responsibility for risk decisions rather than treating security as solely IT's problem.
Related terms
- Audit Committee
- A sub-committee of the board of directors composed principally of independent non-executive directors, responsible for overseeing financial reporting, internal controls, and the...
- CISO (Chief Information Security Officer)
- The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
- First-Line Controls
- Controls owned and operated by the business units and IT functions that process or store information. The first line is accountable for...
- Second-Line Oversight
- The risk management and compliance functions, including the CISO office and the risk function, that set policy, monitor control effectiveness across the...
- Three Lines of Defence
- A governance model that separates security responsibility into three distinct layers: operational management that owns controls (first line), risk and compliance functions...