Skip to main content
Category: Security Policies & Standards

Policy Governance

Also known as: Carver model, Policy Governance Model, Policy Governance®
Simply put

Policy Governance is a structured model for how a board of directors leads an organization, created by Dr. John Carver. Rather than dictating specific day-to-day decisions, it provides an operating framework that helps boards govern in the best interest of the organization's owners or stakeholders. It is sometimes informally called the Carver model.

Formal definition

Policy Governance is an integrated system of governance principles, developed by Dr. John Carver, that defines and guides appropriate board leadership rather than mandating specific operational decisions. Described as a comprehensive set of integrated principles intended to enable owner-accountable governance, it functions as an operating system for boards of directors, distinguishing the board's governing role from operational management. As a board-level governance paradigm, it addresses how boards define ends and delegate authority; it is distinct from information security leadership functions such as those delivered through a virtual or fractional CISO engagement, though its principles of separating governance accountability from operational responsibility parallel that distinction.

Why it matters

Policy Governance matters because it addresses a persistent challenge in organizational leadership: how a board of directors can lead effectively without collapsing the distinction between governing and managing. By providing an integrated framework for how boards define ends and delegate authority, the model helps boards focus on their accountability to the organization's owners or stakeholders rather than becoming entangled in operational decisions that belong to management.

For security leaders and the executives who engage them, the relevance is largely conceptual rather than direct. Policy Governance is a board-level governance paradigm, not an information security function. However, its central principle, separating governance accountability from operational responsibility, parallels an important distinction in security leadership engagements. Just as a board governs without executing daily operations, a virtual or fractional CISO typically advises and directs on strategy, governance, and risk while operational execution and ultimate organizational accountability remain with the client organization and its officers.

Understanding this parallel helps buyers avoid a common category error: treating governance and operational responsibility as the same thing. Recognizing where governing authority ends and operational responsibility begins clarifies expectations in both boardrooms and security leadership arrangements, though the two domains should not be conflated as equivalent functions.

Who it's relevant to

Boards of Directors
Boards are the primary audience for Policy Governance, since the model is designed to define and guide appropriate board leadership. It helps directors focus on governing in the best interest of owners or stakeholders and on delegating authority clearly, rather than managing operations directly.
Executives and Organizational Officers
Executives operating under a board that uses Policy Governance benefit from clearer delegation of authority and defined ends. The model's separation of governing from managing clarifies where operational responsibility and organizational accountability reside, which typically remains with officers and management.
Security Leaders and vCISO Buyers
For those engaging or delivering virtual and fractional CISO services, Policy Governance is relevant chiefly as an analogy. Its principle of separating governance accountability from operational responsibility parallels the distinction between a security leader who advises and directs and a client organization that retains ultimate accountability. It should not be treated as an information security function itself.
Governance Consultants
Consultants who specialize in board effectiveness may use Policy Governance as a structured implementation framework, given that consultation and implementation support are offered specifically for this model.

Inside Policy Governance

Policy Framework Structure
The organized hierarchy of governing documents, typically distinguishing policies (high-level intent and mandates), standards (specific mandatory requirements), procedures (step-by-step instructions), and guidelines (recommended practices). A virtual CISO often helps establish this structure but generally directs and reviews rather than authoring every operational procedure.
Ownership and Approval Authority
The assignment of who drafts, reviews, approves, and maintains each policy. Accountability for approving and enforcing policy typically remains with client executives and officers; a vCISO advises on content and structure but usually does not hold organizational accountability unless a contract specifies otherwise.
Review and Update Cadence
Defined intervals and triggers (such as regulatory change, incidents, or organizational change) for revisiting policies to keep them current. The appropriate cadence often varies by organization and regulatory context.
Regulatory and Framework Alignment
Mapping policies to relevant frameworks or regulations such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR, or CMMC. Alignment supports readiness and demonstrates intent but does not by itself constitute certification or guarantee compliance.
Enforcement and Exception Handling
Mechanisms for monitoring adherence, documenting deviations, and processing approved exceptions. Enforcement generally depends on client cooperation and operational teams; a vCISO typically defines the process rather than executing hands-on enforcement.
Communication and Awareness
Processes to distribute policies, confirm acknowledgment, and educate staff so that documented intent translates into practice. Effectiveness often depends on organizational maturity and stakeholder engagement.

Common questions

Answers to the questions practitioners most commonly ask about Policy Governance.

Does a virtual CISO write and enforce all of our security policies for us?
This is a common misconception. A virtual CISO typically leads and directs policy governance, drafting, and review, but they generally do not unilaterally write and enforce every policy in isolation. Effective policy governance depends on input from business stakeholders, legal, HR, and technical teams, and enforcement usually remains an operational function of the client organization. The vCISO advises on structure, prioritization, and alignment to frameworks, while accountability for adopting and enforcing policies typically stays with the client's officers and process owners. The value of this work often depends heavily on client cooperation and access to stakeholders.
Is policy governance just a technical documentation exercise the security team handles?
No. Treating policy governance as a purely technical or documentation task is a mistake an experienced practitioner would correct. Policy governance is fundamentally a business risk and organizational function that connects security expectations to business objectives, roles, and accountability. While technical teams contribute, policies often require executive sponsorship, cross-functional review, and alignment with legal and regulatory considerations. A vCISO typically frames policy governance as a governance discipline rather than a set of documents produced by IT, which is part of why it is positioned at the leadership level.
How should we prioritize which policies to develop first in a vCISO engagement?
Prioritization typically depends on the organization's risk profile, maturity, and any applicable frameworks or regulatory drivers such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR, or CMMC. In many engagements a vCISO will start by assessing current-state policies, identifying gaps against relevant frameworks, and prioritizing foundational policies that address the highest business risks. The specific sequence often varies by provider and by the client's obligations, so a vCISO usually validates priorities with leadership rather than applying a fixed template.
How often should policies be reviewed and updated?
Review cadence varies by organization, policy type, and applicable framework requirements. Many governance approaches establish periodic reviews along with event-driven updates triggered by changes such as new regulations, significant business changes, incidents, or audit findings. A vCISO typically helps define a review schedule and ownership model so policies remain current, but the discipline of actually performing reviews depends on client processes and stakeholder participation. The cadence should be documented as part of the governance structure itself.
Who is responsible for approving and maintaining policies once a vCISO drafts them?
It is important to separate responsibility from accountability here. A vCISO may lead drafting and recommend approval workflows, but approval and ongoing ownership typically rest with the client organization, often involving executive sponsors and designated policy owners. Legal and organizational accountability for policy decisions usually remains with the client's officers rather than the vCISO, unless a contract specifies otherwise. Establishing clear ownership and an approval chain is often part of the governance framework a vCISO helps put in place.
How does policy governance relate to compliance readiness for frameworks like SOC 2 or ISO 27001?
Policies are typically a foundational element of readiness for frameworks such as SOC 2 or ISO 27001, but their presence alone does not guarantee certification or compliance. A vCISO can support readiness by helping align policies to framework requirements and mapping controls, yet certification generally requires implemented controls, evidence, and independent assessment or audit. It is important to distinguish supporting readiness from asserting compliance or certification, and outcomes may vary based on organizational maturity, control implementation, and the assessment process itself.

Common misconceptions

Policy governance is a documentation exercise that a virtual CISO can complete and hand off, after which the organization is compliant.
Producing policy documents supports readiness but does not by itself deliver compliance or certification, which typically require sustained operation, evidence, and often independent assessment. Governance is an ongoing function, and accountability for maintaining and enforcing policy usually remains with the client organization.
A virtual CISO who establishes policy governance is responsible for enforcing the policies day to day.
A vCISO generally advises on and directs policy structure and content but does not typically perform hands-on operational enforcement, monitoring, or exception administration unless explicitly contracted. Enforcement responsibility usually sits with internal teams and management.
Policy governance is a purely technical control-writing task.
Policy governance is primarily a governance and business risk function that ties security intent to organizational objectives, roles, and accountability. Its value often depends on executive support, stakeholder cooperation, and organizational maturity rather than technical drafting alone.

Best practices

Define a clear document hierarchy that separates policies, standards, procedures, and guidelines so intent is not conflated with operational instructions.
Assign explicit ownership and approval authority within the client organization, keeping accountability with executives and officers rather than the advising vCISO unless a contract specifies otherwise.
Establish a defined review cadence and change triggers so policies remain current as regulations, frameworks, and business conditions evolve.
Map policies to the frameworks or regulations relevant to the organization to support readiness, while being explicit that this supports rather than guarantees compliance or certification.
Build a documented exception and enforcement process, and confirm internal teams have the capacity and cooperation to operate it.
Pair policy publication with communication, acknowledgment, and awareness activities so documented intent is understood and applied across stakeholders.