Security & Privacy Governance
Last updated
Last updated
Setting the strategic direction of the program
Steering committees approve security projects
Better accountability
Senior management
Perform a risk analysis to quantify the risk
Current state and desired future state
At detail requirements
Define the security strategy
Increased Business Value
Analyze the current business strategy
Ensuring trust in data
WHY?
The development of trust in the integrity of information among stakeholders should be the primary goal of information security governance. Review of internal control mechanisms relates more to auditing, while the total elimination of risk factors is not practical or possible.
Proactive involvement in business decision making implies that security needs dictate business needs when, in fact, just the opposite is true. Involvement in decision making is important only to ensure business data integrity so that data can be trusted.