A-Overview Flashcards
What an effective governance program will use
Balanced scorecard, metrics, and other means to monitor these or other key processes.
Information security governance
A set of activities that are established so that management has a clear understanding of the state of the organization’s security programs, its current risks, and its direct activities
Issues that Information security can create
business and people issues
Goal of the security program
To continue to contribute toward fulfillment of the security strategy, which itself will continue to align to the business and business objective.
IT’s role in a successful information security governance
An effective IT governance is required. Without IT governance, information security governance will not be able to reach its full potential
Downward vision flow information security governance
1- Business vision to 2- Business strategy ; to 3- Business Objective ; to 4- IT security Strategy ; to 5- IT security strategy; to 6- Security Policy; to 7- Security standards ; to 8- Security process ; to 9-Security Metrics
Purpose of security governance
To align the organization’s security program with the business program with the needs of the business.
Security Policy
Should at minimum reflect directly the mission, objectives, and goals of the organization.
Standards
Help to drive a consistent approach to solving business challenges
Processes
Formalized descriptions of repeated business activities that include instructions to applicable personnel.
Two keys results of an effective security governance program
• Increased trust Customers, suppliers, and partners trust the organization to a greater degree when they see that security is managed effectively. • Improved reputation The business community, including customers, investors, and regulators, will hold the organization in regard.
When does governance begin
With the establishment of top-level strategic objectives that are translated into actions, policies, procedures, and other activities
Term information security governance
It refers to collection of top-down activities intended to control the security organization to ensure information security supports the business.
Ojectives
Desired capabilities or end states, ideally expressed in archivable, measurable terms.
Strategy
Plan to achieve one or more objectives