The eleven characteristics of effective security governance are critical for an effective enterprise information security information program. They are: It is an institution-wide issue Leaders are accountable It is viewed as an institutional requirement (cost of doing business) It is risk-based Roles, responsibilities and segregation of duties are defined It is addressed and enforced in policy Adequate resources are committed Staff are aware and trained A development life cycle is required