Governance Without Architecture Is Incomplete: The Security Manager Becomes an Architect

Navigation Links: not applicable for this article (no live internal URLs captured yet; consistent with Chapter 26's convention).


Part Five: Defensive Engineering

On 3 November 2026, ISACA changes what its flagship security certification tests for.

The change is confirmed on ISACA's own primary page for the Certified Information Security Manager credential, the certification held by a large share of the world's practising security managers: "the CISM Exam Content Outline will be updated effective 3 November 2026" [1]. Updated preparation material goes on sale from 11 September 2026. The final day to sit the current outline is 2 November 2026.

Buried inside that single confirmed sentence is an argument this book has made since its opening chapters. ISACA's own page does not spell out what changes, so the substance has to come from elsewhere, and that is where this chapter has to be careful before it is useful.

Two Content Areas That Did Not Exist Before

Two training providers, ThinkBit and SpocLearn, independently and directly confirm the substance of the change, and they agree with each other on the specifics while framing them differently, which is the standard I look for before treating a claim as solid rather than merely repeated [2] [3].

The CISM exam gains two content areas that have never appeared on it before. Enterprise Architecture assesses how business capabilities, data flows and applications integrate across an organisation. Information Security Architecture assesses how identity models, segmentation and control layers integrate across hybrid and cloud environments. Read those two sentences again slowly. They are not asking a security manager to appreciate architecture from a distance. They are asking a security manager to be tested on it.

The domain weighting shifts in the same direction. Information Security Governance moves from a current-frameworks focus toward strategy. Information Risk Management moves from point-in-time assessment toward risk appetite. Security Programme Development, which previously covered operational controls alone, now includes architecture. Incident Management consolidates toward resilience.

Put plainly: a candidate who could pass the current CISM exam by knowing frameworks, controls and incident playbooks will not automatically pass the exam that opens on 3 November 2026. They will need to explain how a business capability maps to the data flowing through it, and how an identity model extends across whatever mix of hybrid and cloud infrastructure their organisation actually runs. That is architecture. Historically, it has sat two floors up, with a different reporting line, tested by a different credential.

The Phrase I Am Not Going to Attribute to ISACA

I want to be direct about something before I go further, because getting this wrong would undercut the very point this chapter is making.

The phrase that gives this chapter its title, that governance without architecture is incomplete, is not something ISACA said. I went looking for it in ISACA's own primary page and it is not there, in any form. It traces to one training provider's own commentary on the exam change, offered as that outlet's analytical conclusion in a section about the architecture content area, not as a quotation from ISACA [3]. Another well-regarded outlet reporting the same story reaches for the same kind of framing independently, which tells you something too: even people covering this accurately are already reaching for architecture-convergence language to describe it. But reaching for a framing and attributing a quotation are different acts, and I am not going to blur them.

So here is the honest version. ISACA did not say governance without architecture is incomplete. ISACA restructured its exam so that a security manager cannot pass it without demonstrating architecture fluency. The restructuring is the evidence. The sentence in this chapter's title is my own conclusion from that evidence, not ISACA's words in quotation marks, and if you see anyone attribute that exact phrase to ISACA directly, you are reading a training provider's commentary dressed as a primary source.

That distinction matters more in an election year than it would in any other year, and it matters for a book that has spent twenty-six chapters insisting that named claims trace to what was actually said, not to what someone wished had been said. It also happens to make the chapter's opening hook stronger, not weaker: "ISACA just changed what it tests for" is a claim I can stand behind completely. A quotation that does not check out is a claim I cannot.

Three Validators, and Why the Third One Is Different

This is the third distinct kind of external validation this book has logged in a matter of weeks, and the three are not interchangeable.

A recent chapter in this Part described a major enterprise software vendor building a cross-platform agent discovery tool because it could no longer see what its own customers had deployed. That is market validation: a vendor with a commercial interest in selling governance tooling concluding that governance tooling is needed. Another recent chapter described Australia and New Zealand diverging on statutory AI disclosure obligations. That is regulatory validation: a state imposing a compliance requirement.

ISACA's exam change is neither. A credentialing body has no commercial interest in selling you architecture tooling, and it has no statutory power to compel you to hold its certification. Its only asset is the credential's integrity: the promise that a CISM holder actually knows what the letters claim they know. When a body with that specific, narrow incentive concludes that architecture fluency belongs inside the definition of a qualified security manager, it is not selling you anything and it is not regulating you. It is the profession checking its own credential against what the job now actually requires.

This is the professional-standards layer answering a question Generative AI 2026 named the Governance Gap: the persistent, measured distance between how widely organisations use AI and how few have validated oversight in place. Everything this book has tracked since Chapter 1 describes some version of that gap failing to close on its own. ISACA's exam change does not close it either, and I am not going to claim otherwise. What it does is narrower and, I think, more useful: it identifies, from inside a licensing body rather than from a vendor pitch deck or a government report, which specific competency the gap has been a symptom of missing. Not "AI awareness" in the vague, everything-and-nothing sense that phrase usually carries. Architecture fluency, named as a content area, tested as a content area, from 3 November 2026.

When Governance Tries to Measure Risk It Cannot Map

There is a second, adjacent finding worth putting alongside the exam change, because it shows what happens when the architecture competency gap has an operational cost attached rather than a credentialing one.

Reporting published on 31 July 2026 by a compliance advisory firm, Lazarus Alliance, cites its own proprietary assessment data: 62 per cent of initial AI Risk Management Framework self-assessments miss the measurable-metrics standard that ISO 27001 Clause 6.1.2 requires [4]. I want to be precise about what that figure is and is not. It is one firm's own compliance-assessment data, presented by that firm's own consultant, and it has not been independently replicated by a second source. Treat it as illustrative of a pattern, not as a settled industry-wide statistic, and do not let anyone hand it to you as more certain than that.

What it illustrates, treated with that caveat firmly attached, is consistent with everything else in this chapter. Organisations trying to govern AI risk formally, using NIST's four functions of Govern, Map, Measure and Manage, are tripping over the same absence the CISM exam change is responding to: a mapped, measurable control architecture to govern through. You cannot measure what you have not architected. A governance framework applied to an unmapped estate produces exactly the kind of narrative compliance that looks complete on paper and fails the first time someone asks for the underlying control.

What This Book Already Told You About the Same Boundary

If you have been reading this series from earlier in Part Four, none of this should feel unfamiliar, because you have already met the argument from the other direction.

Chapter 12, The Sixth Pillar: Agent Identity and the New Perimeter [5], introduced Agent Identity, Agent Registry and Agent Gateway as the mitigation pattern that finally closes out the three conditions of the compound risk this book calls the Trifecta. That pattern only works if the person running it can answer a specific architectural question: what access has been granted, to what data, under what conditions, and how does that map across the organisation's actual hybrid and cloud footprint? An agent not in the registry has no governed identity. A security manager who cannot read that registry as an architectural artefact, not just a security control, cannot keep it honest. That is exactly the competency ISACA's Information Security Architecture content area now tests for.

Chapter 3, Zero Trust Fundamentals for Data Scientists and ML Engineers [6], made the same bridging argument from the opposite professional direction: that two communities operating with separate vocabularies, security architects and machine learning engineers, needed to share a working understanding of identity, authentication, authorisation and segmentation before either could deploy safely. That chapter argued the two communities should share vocabulary. ISACA's exam change is a licensing body concluding they must, at least for the security-manager half of that pairing.

Neither Chapter 12 nor Chapter 3 used the term architecture as decoration. Both used it because the argument does not work without it. ISACA's exam change is the clearest evidence yet that a body with no stake in this book's argument reached the same conclusion independently.

A Crosswalk: What the New Exam Content Asks, and Where This Book Already Covers It

If you hold a CISM credential, or you manage people who do, the honest next question is not "should I care about architecture." It is "which specific gaps do I have, and where do I start closing them." The table below maps ISACA's two new content areas to material already covered in this series, so the crosswalk is something you can act on this week rather than a reading list for next year.

CISM Content Area (from 3 Nov 2026) What It Actually Asks Where This Book Already Covers It
Enterprise Architecture: business capabilities, data flows, applications integration Can you trace a business capability through the systems and data that support it, across the whole organisation, not just your own team's slice? Chapter 3 builds the shared vocabulary between security and technical teams that this tracing depends on. Chapter 12's Agent Registry is a live example of a capability-to-data-flow map built for a specific governance purpose
Information Security Architecture: identity models across hybrid and cloud Can you describe how an identity is established, verified and scoped as it moves between on-premises, cloud and third-party environments? Chapter 12's Agent Identity pattern; the NZISM v3.9 authentication baseline covered earlier in Part Two
Information Security Architecture: segmentation and control layers Can you explain where your control boundaries actually sit, rather than where a vendor's default configuration put them? Chapter 19's Vendor-Decides Pattern [7] names exactly this failure mode: enterprise governance emerging from accumulated vendor defaults rather than deliberate architectural choice
Domain weighting: strategy and risk appetite over point-in-time assessment Can you speak to your organisation's risk appetite as an ongoing position, not a snapshot from the last audit cycle? The Governance Gap concept this series has referenced since Part One frames exactly this distinction: adoption is continuous, governance has too often been point-in-time

A five-question Monday-morning self-assessment. You do not need to wait for exam preparation material in September to start finding your own gaps.

  1. Can you name every system your organisation's AI agents touch, and who registered each one?
  2. Could you explain, in one paragraph, how your identity model extends across your hybrid and cloud estate, without asking someone else to draw the diagram first?
  3. If a vendor's default governance setting were wrong for your environment, would you know, or has the vendor already made that decision for you?
  4. Can you map your last AI risk self-assessment's Govern, Map, Measure and Manage findings to specific, checkable controls, rather than narrative statements?
  5. Could you draw your organisation's control layers from human, to workload, to agent, without calling the architecture team first?

If more than one of those gave you pause, you have just located, without an exam fee, roughly the same gap ISACA's restructured content outline is designed to test for.

What New Zealand Evidence Does Not Yet Say

I looked for New Zealand-specific evidence that hiring criteria or role definitions for security managers and enterprise architects are shifting in response to this exam change, or in response to the broader convergence this chapter describes. I did not find it. What came back were generic vacancy counts on job boards, which tell you how many roles exist, not whether employers are already screening for the competency ISACA is about to test for. Vacancy volume is not evidence of a convergence trend, and I am not going to present it as if it were.

That is a genuine gap, not a hedge. CISM is a globally administered credential that a substantial number of New Zealand security managers hold, so the international exam change reaches this market directly even without a documented local commentary trend, and readers here can draw that inference for themselves. If your organisation is already adjusting position descriptions or interview criteria in response to this change, that is worth documenting properly rather than assumed from the outside, and it is exactly the kind of local evidence this series would want to build on in a future instalment.

The Question Worth Sitting With

A security manager renews a CISM certification she has held since 2019. She has never drawn an architecture diagram professionally. That has always been someone else's job, two floors up, on a different reporting line.

In September, the email arrives: the exam outline is changing on 3 November, and her continuing-education requirements now reference two content areas she does not recognise. She opens the outline. It asks her to explain how business capabilities, data flows and applications integrate across an organisation, and how identity models, segmentation and control layers integrate across hybrid and cloud environments.

She forwards it to the enterprise architect two floors up, half as a joke: "Looks like I'm supposed to do your job now."

He replies within the hour, and he is not joking back: "Funny you say that. I got asked last week why our AI agent deployments aren't in the security risk register. I said that's not an architecture question, it's a governance question. Turns out it's both, and I don't think either of us has been treating it that way."

  • ISACA restructures the CISM exam from 3 November 2026, adding Enterprise Architecture and Information Security Architecture as tested content for the first time.
  • A credentialing body's own exam change is a third, structurally distinct validation channel, next to market validation and regulatory validation.
  • The crosswalk above maps both new content areas to material this series has already covered, so the gap-finding starts this week.
  • Run the five-question self-assessment before your own renewal notice arrives.

The competency ISACA just made mandatory for security managers already has open governance built into how enterprises actually implement it. TOGAF, the enterprise architecture methodology this book's own AI-EA Model extends, is maintained not by a vendor but by The Open Group, a member-driven consortium that publishes it as an open standard rather than licensing it as proprietary intellectual property [8]. The identity layer the Information Security Architecture content area tests, extending an identity across hybrid and cloud environments, runs in most enterprises on OAuth 2.1, the IETF's in-progress consolidation of OAuth 2.0 [9], and OpenID Connect, the identity layer the OpenID Foundation maintains on top of it [10], rather than on any single cloud provider's proprietary protocol. A credentialing body can mandate the competency. It cannot mandate that the standards underneath it stay maintained, which is the quieter, harder problem open governance always carries.

The same convergence is already binding at the regulatory layer, not only the credentialing one. The European Union's NIS2 Directive requires members of the management bodies of essential and important entities to follow training sufficient to identify cybersecurity risks and assess the adequacy of an organisation's risk-management practices [11]: an architecture-literacy mandate written into law, not into an exam syllabus. The technical substance ISACA's Information Security Architecture content area now tests traces to the same foundation the United States' National Institute of Standards and Technology formalised in Special Publication 800-207 [12], identity rather than network location as the unit that architecture and governance both have to verify. A professional body testing the competency, a regulator mandating it for boards, and a standards body defining its technical shape are three institutions converging on one answer: the people accountable for security can no longer treat architecture as someone else's floor.

If your own CISM renewal notice arrives with two content areas you have never been tested on, will you already know which of your organisation's agents, data flows and identity boundaries you could explain end to end, or will you be forwarding the email to someone else's desk?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. Zero Trust Architecture for the Agentic Enterprise is the first book in The Hamberger Report series, providing practitioners with deployable patterns and configurations for securing AI-driven systems.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


References

[1] ISACA. "CISM® Exam Content Outline." isaca.org. Confirms the 3 November 2026 effective date; does not itself disclose the substance of the change. https://www.isaca.org/credentialing/cism/cism-exam-content-outline

[2] ThinkBit Training. "ISACA will update the CISM exam on 3 November 2026." Directly fetched by Article Researcher, 6 August 2026. Primary secondary source for the two new content areas and the domain-weighting detail. https://thinkbittraining.co.uk/2026-cism-exam-changes/

[3] SpocLearn. "CISM 2026 Update: New ISACA Exam Changes." Directly fetched by Article Researcher, 6 August 2026. Source of the "governance without architecture is incomplete" commentary, which this chapter attributes to SpocLearn's own analysis, not to ISACA. https://www.spoclearn.com/blog/cism-exam-update-isaca-changes/

[4] Michael Peters for Lazarus Alliance, published via Security Boulevard. "NIST AI RMF: 4 Risk Management Strategies." 31 July 2026. Single-source data on the 62 per cent AI RMF self-assessment figure; presented with that caveat throughout this chapter. https://securityboulevard.com/2026/07/nist-ai-rmf-4-risk-management-strategies-by-lazarus/

[5] Chapter 12: The Sixth Pillar: Agent Identity and the New Perimeter. EA Thursday (Zero Trust). Agent Identity, Agent Registry and Agent Gateway pattern referenced.

[6] Chapter 3: Zero Trust Fundamentals for Data Scientists and ML Engineers. EA Thursday (Zero Trust). Cross-professional bridging argument referenced.

[7] Chapter 19: The Delegation Problem. EA Thursday (Zero Trust). Vendor-Decides Pattern referenced.

[8] The Open Group. "TOGAF." Vendor-neutral standards consortium; independently verified via direct web fetch, 6 August 2026. https://www.opengroup.org/togaf

[9] IETF OAuth Working Group. "The OAuth 2.1 Authorization Framework" (draft-ietf-oauth-v2-1). In-progress consolidation of OAuth 2.0; independently verified via direct web fetch, 6 August 2026. https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1-14

[10] OpenID Foundation. "How OpenID Connect Works." Independently verified via direct web fetch, 6 August 2026. https://openid.net/developers/how-connect-works/

[11] European Parliament and Council. "Directive (EU) 2022/2555 (NIS 2 Directive), Article 20." 14 December 2022. Management body training mandate; independently verified via direct web fetch, 6 August 2026. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555

[12] National Institute of Standards and Technology. "Special Publication 800-207: Zero Trust Architecture." August 2020. Independently verified via direct web fetch, 6 August 2026. https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf

Next
Next

The Agent Sprawl Nobody Provisioned