Security program management and administrative activities
Information security program management includes activities to direct, monitor, and control the procedures related to information security. It includes both short-term and long-term planning for the achievement of security objectives. The security manager should ensure that the security program supports the requirements of management. In most organizations, the security manager is responsible for executing the security program. The information security steering committee, which consists of senior leadership from relevant functions of the organization, is responsible for ensuring that security objectives are aligned with business objectives. Senior management represented in the security steering committee is in the best position to support and advocate for the information security program. The role of the steering committee, as well as the security manager, is of utmost importance to ensure that security resources are utilized...