Security Program Management and Administrative Activities
Information security program management includes activities to direct, monitor, and control procedures related to information security. It includes both short-term and long-term planning for the achievement of the organization's security objectives. A security manager should ensure that the security program supports the requirements of management. In most organizations, a security manager is responsible for executing the security program. An information security steering committee that consists of senior leadership from the relevant functions of the organization is responsible for ensuring that the security objectives are aligned with the business objectives. Senior management represented in the security steering committee is in the best position to support and advocate the information security program. The role of the steering committee, as well as the security manager, is of utmost importance to ensure that security resources...