GOVERNANCE - Effective Information Security Governance - Business Goals and Objectives
4 important questions on GOVERNANCE - Effective Information Security Governance - Business Goals and Objectives
What is corporate governance
- Corporate governance is the set of responsibilities and practices
- Exercised by and senior management
- With the goals of providing strategic directions, ensuring objectives are achieved
- Ascertaining that risk is managed properly
- Verifying resources are used properly
What needs to be established to achieve effective information security governance?
What are the contents of a governance framework?
- Security strategy linked with business objectives
- Governing security policies addressing each aspect of strategy, controls and regulation
- A complete set of standards for each policy
- An effective security organizational structure
- Defined workflows and structures that assist in defining responsibilities and accountability for information security governance.
- Institutionalized metrics and monitoring processes to ensure compliance, provide feedback and provide the base for appropriate management decisions
- Higher grades + faster learning
- Never study anything twice
- 100% sure, 100% understanding
What is difference in main requirement between IT and information security
IT: focus on adequate level of performance
IS: managing risk to an acceptable level
The question on the page originate from the summary of the following study material:
- A unique study and practice tool
- Never study anything twice again
- Get the grades you hope for
- 100% sure, 100% understanding