Security governance
Security at CERN is law, not advice: oc5 binds every user, the computer-security-officer enforces it, the computer-security-board legislates the subsidiary-rules, and the cis-v8-audit of 2023 drove the modern control set — secure-sdlc, mfa-rollout, password-policy.