In addition to business alignment and security ownership, which of the following is MOST critical for information security governance?