It is important to understand what is important to your organization in order to properly protect the organization from potential threats. The information security professional must look beyond just information technology and take a look at the organization they work for and understand its concerns.
The information security professional must understand documents such as the corporate mission and vision statements. These documents answer questions such as:
- What does the organization do?
- Do you make car tires, or do you provide services to the elderly?
- Who are the organization's customers?
- Who receives your services?
- Who is the organization?
- What is the organizational culture? How does the organization want to be viewed?
- Who are your third-party partners within your business structure?
- Use Target, Home Depot...