Information security program objectives
A security manager should understand the following objectives of a security program while implementing the program:
- To provide maximum support to business functions
- To minimize operational disruption
- To implement the strategy in the most cost-effective manner
After establishing the objectives, key goal indicators (KGIs) to reflect these objectives need to be developed. The next step is to determine the current state of security. The current state should be compared with established objectives and identified gaps should be addressed to improve the security processes.
Key aspects from a CISM exam perspective
The following are some of the key aspects from an exam perspective:
Questions
- The security manager notes that senior management is dissatisfied with the current state of information security. To address this, what...