Security Budget
Budgeting plays a significant role in the effective implementation of an information security program. The availability of adequate security personnel and other security resources is dependent on the security budget. An information security manager should be familiar with the budgeting process and methods used by the organization.
Primarily, the security budget is derived from and supported by the information security strategy. Before seeking approval for the budget, the security manager should ensure that senior management has approved the strategy and that there is consensus from the other business units. This is a key element in a successful budget proposal.
Apart from routine expenditure, the budget should also consider unanticipated costs. Generally, in the area of incident response, it is difficult to predict expenditure. A security manager may require the obtaining of external services to support the incident response processes, where the organization does...