Evaluate, apply, and sustain security governance principles
1.3.1Alignment of the security function to business strategy, goals, mission, and objectives
1.3.2Organizational processes (e.g., acquisitions, divestitures, governance committees)
1.3.3Organizational roles and responsibilities
1.3.4Security control frameworks (e.g., ISO, NIST, COBIT, SABSA, PCI, FedRAMP)
1.3.5Due care/due diligence