Senior Management Commitment
For effective implementation of security governance, support and commitment from senior management is the most important prerequisite. A lack of high-level sponsorship will have an adverse impact on the effectiveness of security projects.
It is very important for the information security manager to gain support from senior management. The most effective way is to ensure that the security program continues to be aligned with, and supports, the business objectives. This is critical for promoting management support. Senior management is more concerned about the achievement of business objectives and will be keen to address all risks impacting key business objectives.
Obtaining commitment from senior managers is very important to ensure appropriate investment in information security, as you will explore in the next section.
Information Security Investment
Any investment should be able to provide value to the business. The primary driver for investment...