All organisations must develop their **[[Security Posture]]**. Elements of the security and risk management domain that impact an organisation's security posture include: - Security goals and objectives - Risk mitigation processes - Compliance - Business continuity plans - Legal regulations - Professional and organisational ethics Information security, or **InfoSec**, is also related to this domain and refers to a set of processes established to *secure information*. An organization may use playbooks and implement training as a part of their security and risk management program, based on their needs and perceived risk. There are many InfoSec design processes, such as: - Incident response - Vulnerability management - Application security - Cloud security - Infrastructure security As an example, a security team may need to alter how personally identifiable information (PII) is treated in order to adhere to the European Union's General Data Protection Regulation (GDPR).