← ISC2 CC: cybersecurity foundations in practice
02 / 5 · 30 MIN

Governance, continuity, and awareness

Support decisions and continuity with clear metrics and communication.

Concept and mechanism

Governance provides direction, responsibilities, and criteria for deciding and tracking risk. An entry-level analyst contributes reliable records, communication, and process execution rather than inventing authority to accept exceptions. Indicators need scope, date, and denominator. Eight unsupported servers among forty represent twenty percent of the population, not a twenty-percent incident probability. A useful dashboard identifies who will address exposure and by when. Awareness is operational too: when facing an urgent data-change request, verify through an independently known contact. Replying to the same email or using its supplied number may simply return to the same unauthenticated party.

Guided application

During a fictional outage, the team sustains essential requests through an approved manual list while IT restores the application. The first effort supports business continuity and the second technical recovery. When the application returns, reconcile completed and outstanding work to prevent duplicates. Define who may declare the return to normal flow. Exercises have different objectives: a tabletop may reveal outdated contacts and unclear decisions, but it does not measure the speed of a restoration never executed. In reporting, acknowledge what was rehearsed and plan checks for gaps. A short meeting does not prove RTO, and mentioning backups does not establish recoverability. This discipline helps the team communicate outcomes without turning intent into guarantees.

IN PRACTICE

8/40 = 20% unsupported assets; the value describes exposure, not incident probability.

Common pitfalls

Urgency as authenticity; same channel as confirmation; tabletop as restoration; manual process without reconciliation.

Related topics: Security principles and conduct · Identity and access lifecycle · Networks, cloud, and boundaries

Take this idea with you

Communicate scope, evidence, and outstanding work explicitly.

Create account

Reference: Cybersecurity Framework 2.0 · CC examination outline effective 2026-09-01; PDF v01/2026