📖 What is Three Lines of Defense?
The Three Lines of Defense is a governance model that separates operational management, risk oversight, and independent assurance. The lines consist of business operations, the risk/compliance function, and internal audit.
"On the exam, remember that the Third Line (Audit) must remain completely independent from the first two lines."
📚 Certification: Certified Information Security Manager (CISM)
🔑 What are the Key Concepts of Three Lines of Defense?
- ▸ The First Line consists of business operations and management who own the risks and are responsible for implementing internal controls to mitigate them.
- ▸ The Second Line comprises risk management and compliance functions that establish policies, provide oversight, and monitor the effectiveness of first-line controls.
- ▸ The Third Line is internal audit, providing independent and objective assurance to the board and senior management regarding the overall governance framework.
- ▸ Independence is paramount for the Third Line; auditors must not be involved in designing or implementing the controls they are tasked with auditing.
- ▸ Effective coordination between all three lines ensures that risks are identified, managed, and validated without gaps or redundant efforts across the organization.
🎯 How does Three Lines of Defense appear on the CISM Exam?
You may be asked to identify which group is responsible for the day-to-day execution of security controls. The correct answer will be the first line of defense.
A scenario might describe a conflict where the risk management team is performing an internal audit. You must recognize this as a violation of the third line's independence.
Expect questions regarding the reporting structure of the internal audit function, specifically their need to report to the board or audit committee to maintain objectivity.
❓ Frequently Asked Questions
Can the risk management team (Second Line) also perform internal audits?
No. While the second line monitors and oversees, the third line must remain independent. Having the second line audit itself creates a conflict of interest and undermines objective assurance.
Who is ultimately accountable for the risks identified in the first line?
The business process owners and operational managers are accountable. The second and third lines provide oversight and assurance, but they do not own the operational risk.