Scrum Guidance Body

The Scrum Guidance Body (SGB) is an optional organizational body made up of guidance documents and/or subject-matter experts that sets enterprise-level objectives and rules for quality, regulatory compliance, security, and other critical governance areas.

Key Points

  • Optional construct at the organizational level; not a required Scrum Team role.
  • May consist of documents, experts, or both, providing standards and guardrails.
  • Focuses on quality, regulations, security, and other enterprise policies and controls.
  • Guides and aligns teams without replacing the Product Owner or Scrum Master.

Example

A financial services company creates an SGB that publishes secure coding standards, data retention rules, and a minimum Definition of Done that includes regulatory checks. Scrum Teams consult these materials and, when needed, meet with SGB experts to clarify how to satisfy compliance during Sprint Planning and reviews.

PMP Example Question

Which activity best reflects the purpose of a Scrum Guidance Body (SGB) in an organization using Scrum?

  1. Approving each team's Sprint Backlog before the Sprint starts.
  2. Publishing enterprise security and compliance standards that all Scrum Teams must follow.
  3. Prioritizing features in the Product Backlog across all teams.
  4. Directing how Scrum Masters conduct the Daily Scrum.

Correct Answer: B — Publishing enterprise security and compliance standards

Explanation: The SGB provides organization-wide guidance such as quality, security, and regulatory standards; it does not manage Sprint Backlogs, set backlog priorities, or dictate team ceremonies.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Become an AI-First Agile Leader!

HK School of Management helps you apply AI to Agile work with practical, prompt-based workflows for real-world Scrum challenges. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More