Security budget
Budgeting plays a significant role in the effective implementation of an information security program. The availability of adequate security personnel and other security resources is dependent on the security budget. The information security manager should be familiar with the budgeting process and methods used by the organization.
Primarily, the security budget is derived from and supported by the information security strategy. Before seeking approval for the budget, the security manager should ensure that senior management has approved the strategy and other business units have a consensus on the security strategy. This is a key element in a successful budget proposal.
Apart from routine expenditure, the budget should also consider unanticipated costs. Generally, in the area of incident response, it is difficult to predict the expenditure. The security manager may require obtaining external services to support the incident response processes where an organization...