This is a very minor issue. I just want to bring to this up to the community. In Control Map, Governance is always listed last. Ideally, it should be listed first where the Information Security program is started before building the policies and procedures. The order presented is contrary how we explain governance to our customers and their leadership.
- Policies
- Procedures
- Governance:
I think this order makes more sense when looking at hierarchy
- Governance:
- Policies
- Procedures

