HomeDomainsCyber Governance
Discipline 01

Cyber Governance

Board-level oversight, policies and operating models aligned to NCA-ECC, NIST and ISO — run as one programme, with a single view the board can actually read.

At a glance
  • OwnerBoard, CISO, GRC office
  • AnchorsNCA-ECC · ISO/IEC 27001 · NIST SP 800-53
  • CadenceQuarterly to the board, monthly to management
  • OutputPosture, exceptions, decisions
Discipline 01
Why it matters

Cyber Governance

Cyber governance is the part of security that answers to the board: who owns which risk, which policies bind the organisation, how the control environment is measured, and what gets escalated when it slips. Regulators in the Gulf have made it explicit — NCA-ECC opens with a governance domain, and the UAE, Dubai and Saudi sector regulators all require a named accountable executive and a documented operating model.

The difficulty is rarely the policy text. It is keeping the operating model true: an organisation typically answers to three or four frameworks at once, each with its own governance clauses, and the same steering committee, the same policy set and the same risk appetite have to satisfy all of them without being written four times.

GRCLens treats governance as a structure, not a document. Roles, committees, policies and risk appetite are captured once, mapped to every framework that asks for them, and reported from live assessment and evidence data rather than a slide prepared the night before.

Discipline 01

What the platform does for governance

01

One operating model, every framework

Governance controls from NCA-ECC 1-x, ISO/IEC 27001 clauses 5–6 and NIST's PM family map to a common control model, so one committee charter and one policy set evidence all of them.

02

Policy lifecycle

Policies carry an owner and a review date and are referenced as evidence wherever a governance control asks for them. An overdue review shows on the dashboard as overdue, not as a quiet date in a spreadsheet.

03

Risk appetite that reaches the controls

Appetite statements set the thresholds the KRI engine evaluates against, so 'within appetite' on the board pack is computed, not asserted.

04

Board and executive reporting

Posture, exceptions and decisions in a bilingual executive summary, generated from the same data the assessors work in. English and Arabic from one source.

05

Baseerah analysis

A short, prioritised narrative of where the programme stands and what to act on next — written from the assessment, the evidence and the indicators, never from a template.

06

Multi-tenant by design

Group functions govern several entities from one enterprise view while each subsidiary's data stays isolated in its own schema.

In the platform

How it shows up in a tenant

Governance is not a module of its own; it is what the other modules add up to. These are the places it surfaces.

01

Framework dashboards

Domain-by-domain posture for each enabled framework, with the governance domain first because that is where regulators start.

02

Enterprise View

Every entity's maturity on one screen for group boards, with the Baseerah summary and prioritised actions beneath it.

03

Statement of Applicability

Scope decisions and justifications recorded once and exported in the form each auditor expects.

04

Policies and registers

Owned, dated, linked to controls, and reported when stale.

Library

Frameworks in this discipline

NCA-ECC

NCA Essential Cybersecurity Controls

National Cybersecurity Authority (NCA) · Saudi Arabia

Assess, evidence and report against the Kingdom's Essential Cybersecurity Controls — in Arabic or English, hosted in your own environment.

Open the framework page
ISO/IEC 27001

ISO/IEC 27001:2022 Information Security Management

ISO / IEC · International

Annex A controls, Statement of Applicability, risk treatment and evidence — managed in one place, ready for your certification body.

Open the framework page
NIST SP 800-53

NIST Special Publication 800-53 Rev. 5 — Security and Privacy Controls

U.S. National Institute of Standards and Technology (NIST) · United States / International

Assess and evidence NIST SP 800-53 Rev. 5 controls — the catalogue behind FISMA, FedRAMP and the Risk Management Framework.

Open the framework page
UAE IA (NESA/SIA)

UAE Information Assurance Standard (SIA, formerly NESA)

Signals Intelligence Agency (SIA) — formerly NESA · United Arab Emirates

Assess and evidence the UAE Information Assurance Standard — management and technical controls, prioritised P1 to P4, in Arabic or English.

Open the framework page
Dubai DESC ISR

Dubai Information Security Regulation (ISR) v3 — DESC

Dubai Electronic Security Center (DESC) · United Arab Emirates (Dubai)

Assess and evidence Dubai's Information Security Regulation v3 — including its cloud, data residency, IoT and supply-chain provisions.

Open the framework page
CST CRF

Cybersecurity Regulatory Framework (CRF) — Second Version

Communications, Space & Technology Commission (CST), Saudi Arabia · Saudi Arabia

Assess and evidence CST's Cybersecurity Regulatory Framework across 215 controls, six domains and the CL1–CL3 progression, with reporting built for the annual CST self-assessment.

Open the framework page
NZ PSR

New Zealand Protective Security Requirements (PSR)

New Zealand Government (PSR — hosted by NZSIS) · New Zealand

Assess and evidence the Protective Security Requirements across GOVSEC, PERSEC, INFOSEC and PHYSEC — ready for annual PSR assurance reporting.

Open the framework page
AU PSPF

Australian Protective Security Policy Framework (PSPF)

Australian Government — Department of Home Affairs · Australia

Assess protective security maturity across the PSPF domains — governance, risk, information, technology, personnel and physical security.

Open the framework page
Questions

Cyber Governance

Does GRCLens replace our GRC steering committee?

No. It gives the committee its agenda: live posture per framework, the exceptions that need a decision and the indicators outside appetite, drawn from assessment and evidence data rather than compiled by hand.

Can one policy satisfy governance clauses in several frameworks?

Yes. Each policy lives once and is referenced as evidence wherever a governance control asks for it, across every enabled framework — so one information security policy can evidence NCA-ECC 1-3, ISO/IEC 27001 clause 5.2 and the equivalent NIST control at the same time.

Is board reporting available in Arabic?

Yes. Executive summaries and reports are generated bilingually from the same underlying data, so the Arabic pack and the English pack cannot disagree.

See governance reported from live data

A 30-minute walkthrough of the framework dashboards, the enterprise view and a generated board pack, on your frameworks.