Three Lines of Defence
Definition
A governance model that separates security responsibility into three distinct layers: operational management that owns controls (first line), risk and compliance functions that monitor and challenge (second line), and internal audit that provides independent assurance (third line).
- Field
- Security and risk governance
- First line
- Operational management, owns and runs controls
- Second line
- Risk and compliance, monitors and challenges
- Third line
- Internal audit, provides independent assurance
Common questions
Why does the model insist on separating the second and third lines from operational management?+
If the people running controls also judged their own effectiveness, conflicts of interest would undermine the assessment. Separating risk oversight and audit from day-to-day operations keeps the checking function independent enough to report problems honestly rather than protecting the operational team's performance.
Who does the third line, internal audit, typically report to?+
Internal audit usually reports functionally to the board or an audit committee rather than to the executives whose functions it reviews, which preserves the independence the model depends on and lets audit findings reach governance without being filtered by management.
Related terms
- CISO (Chief Information Security Officer)
- The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
- Audit Committee
- A sub-committee of the board of directors composed principally of independent non-executive directors, responsible for overseeing financial reporting, internal controls, and the...
- First-Line Controls
- Controls owned and operated by the business units and IT functions that process or store information. The first line is accountable for...
- Governance, Risk, and Compliance (GRC)
- An integrated discipline that combines governance structures, risk management processes, and compliance monitoring into a unified programme. GRC platforms and frameworks allow...
- Policy Hierarchy
- The layered document set that translates governance intent into operational requirements. Tiers typically run: information security policy, topic-specific policies, standards, procedures, and...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Second-Line Oversight
- The risk management and compliance functions, including the CISO office and the risk function, that set policy, monitor control effectiveness across the...
- Security Governance
- The set of structures, roles, policies, and accountability mechanisms by which an organisation directs, controls, and monitors its information security activities. Governance...
- Security Steering Committee
- A cross-functional management body, typically chaired by the CISO or Chief Risk Officer, that coordinates security priorities across business units, approves major...
Explained in these topics
- Security Governance Frameworks OverviewA governance model that allocates accountability across: first line (operational teams that own and manage risk), second line (risk and compliance functions th...
- Security Governance Structures and Roles