From the Director - Most Critical Elements for InfoSec Program Success
- Senior management commitment to InfoSec initiatives
- Management understanding of InfoSec issues
- Infosec planning prior to implementation of new technologies
- Integration between business and InfoSec
- Alignment of InfoSec with the organization’s objectives
- Executive and line mgt ownership and accountability for implementing, monitoring and reporting on information security
Some additional elements for InfoSec Program Success are:
- Appropriate employee education and awareness on information asset protection
- Consistent enforcement of InfoSec policies and standards
- Placement of InfoSec within the organization hierarchy
- Budget for InfoSec strategy and tactical plan
- Consistent board/executive management message with regards to InfoSec priorities
- Focus on short-term goals resulting in long-term control weaknesses
One big issue with applying the above elements is that day-to-day priority conflicts continue to put InfoSec on the back burner
|
|
|