Strategic Guidance for Security, Governance, and Compliance
Three related functions
The story: In a bank branch: the vault, guards, and alarms keep money safe, correct, and available when customers want it. The management team decides how the branch makes money without taking foolish risks. The compliance officer makes sure the branch follows banking law and head office rules.
In AI/AWS terms:
- Security protects the confidentiality, integrity, and availability of data, assets, and infrastructure (the vault and guards).
- Governance helps the organization add value and manage risk (management).
- Compliance ensures adherence to requirements across the organization (the compliance officer).
For the exam: Security = confidentiality, integrity, availability. Governance = value and risk. Compliance = following requirements.
Defense in depth
The story: A castle doesn't rely on one wall. It has rules for guards, gatekeepers checking who enters, a moat, outer walls, inner walls, a locked treasury, and lookouts who raise the alarm and respond. If one layer fails, the next one still holds.
In AI/AWS terms: Defense in depth means multiple redundant layers of security controls, so that if one fails, others still prevent, detect, respond to, and recover from threats. The layers:
- Policies, procedures, and awareness (rules for guards)
- Identity and access management, with AWS IAM as the foundation (the gatekeepers)
- Network and edge protection (the moat)
- Infrastructure protection (the outer walls)
- Application protection (the inner walls)
- Data protection (the treasury)
- Threat detection and incident response (the lookouts)
For the exam: Defense in depth = multiple redundant layers. IAM is the foundation of identity and access.
A high-level governance strategy
The story: A school setting rules for phones in class forms a committee with teachers, parents, a lawyer, and the IT person. It decides who writes the rules, who checks risks, and who makes the final call. Then it writes rules covering the whole school day, not just one lesson.
In AI/AWS terms:
- Create an AI governance board or committee: cross-functional, with legal, compliance, data privacy, and AI experts.
- Define roles and responsibilities: oversight, policy making, risk assessment, decisions.
- Implement policies and procedures covering the whole AI lifecycle, from data management to deployment and monitoring.
For the exam: Governance starts with a cross-functional board, clear roles, and policies across the whole lifecycle.