GOVERN-IDENTIFY-SECURE-VALIDATE
Think of it like protecting a house: first, you set the rules for who is in charge; next, you figure out which items are the most valuable; then, you install locks and alarms on those specific items; finally, you test the locks to make sure they actually stop intruders.
A risk-based operational framework that prioritizes security efforts by first establishing governance, then mapping critical assets (crown jewels), applying targeted technical controls to those assets, and concluding with rigorous validation to ensure the security measures are effective.
The Practical Cybersecurity Decisions (PCD) framework: GOVERN -> IDENTIFY -> SECURE -> VALIDATE. Ethan Seow's own decision framework; it parallels but is distinct from NIST CSF, and starts from the Crown Jewels. (C4AIL / Practical Cyber.)