Security governance sounds boring until you realize it shows up in interviews.
Know the difference:
Policy = what must be done and why
Standard = mandatory rule
Procedure = exact steps
Guideline = recommended best practice
This is beginner-friendly, but it also shows maturity.