This document proposes an Information Security Governance Framework to help corporate executives better govern information security activities. The framework combines and relates existing information security schemes and provides a unified way for executives to direct, monitor, and evaluate security-related work. It is needed because most companies currently take a bottom-up approach to security that is not well-aligned with corporate governance. The proposed framework defines the key elements and interfaces of an Information Security Governance system to address issues and overcome difficulties in how companies govern security.