Defining an Information Security Program Roadmap
For the effective implementation of a security program, it is recommended to develop a roadmap covering the different stages with clear objectives to be achieved during each stage. The initial stage of program development is to have discussions with the concerned stakeholders, such as business units, legal, HR, and finance. This will help the security manager determine the security requirements of different units.
In the second stage, security requirements should be formalized and the basic security policy should be drafted, and approval should be obtained from senior management. A security steering committee consists of officials from different business functions. It plays an important part in the finalization of security requirements. In the third stage, members of the security steering committee emphasize the promotion of security awareness as a part of the policy and conduct security reviews to see whether they are in compliance...