All organisations must develop their **[[Security Posture]]**. Elements of the security and risk management domain that impact an organisation's security posture include:
- Security goals and objectives
- Risk mitigation processes
- Compliance
- Business continuity plans
- Legal regulations
- Professional and organisational ethics
Information security, or **InfoSec**, is also related to this domain and refers to a set of processes established to *secure information*.
An organization may use playbooks and implement training as a part of their security and risk management program, based on their needs and perceived risk. There are many InfoSec design processes, such as:
- Incident response
- Vulnerability management
- Application security
- Cloud security
- Infrastructure security
As an example, a security team may need to alter how personally identifiable information (PII) is treated in order to adhere to the European Union's General Data Protection Regulation (GDPR).