Cybersecurity governance requires strategic direction and impetus. It depends on commitment, resources and
responsibility for cybersecurity management and it requires a means for the board to determine whether its intent has
been met. Effective governance can be accomplished only by senior management involvement in approving policy
and by appropriate monitoring and metrics coupled with reporting and trend analysis.