Chapter 3 - Governance and Information Security Planning
Chapter 3 - Governance and Information Security Planning
Chapter 3 - Governance and Information Security Planning
(ISM811S
Chapter 1 – Introduction to Information Management and Assurance
Dr Mercy Chitauro
Outline
1. What is Security
2. What is Management
3. Principles of Information Security
4. Project Management
5. Homework
Learning outcomes
• Identify vital organisational stakeholders
involved in information security
planning;
• Discuss information security planning in
the context of the organisation and IT
strategic planning;
• Discuss information security governance
and how to implement it;
• Implement an information security
program.
Introduction
Planning:
• Is creating action steps toward goals, and
then controlling them
• Provides direction for the organization’s
future
Top-down method:
• Organization’s leaders choose the direction
• Planning begins with the general and ends
with the specific
Information Security
Planning
Information Security Committee
• Information security committee
– Employees
– Management
– Stockholders
– Other outside stakeholders
Introduction
Organisational leadership
Security Committee
General objectives
Specific objectives
Precursors to planning
• Effective planning should be accompanied by
a vision, mission, and value statements.
• They convey the ethical, entrepreneurial, and
philosophical management approaches of the
organisation.
• Mission statement:
– Declares the business of the organization
and its intended areas of operations
– Explains what the organization does and for
whom
– Example: Random Widget Works, Inc.
The Mission designs and manufactures quality widgets,
Statement associated equipment and supplies for use in
modern business environments
– Many organisations require each division
including infosec to to generate their own
mission statement
– Vision states where the organisation wants
to go and mission statement describes how it
wants to get there
Mission/Vision
Statement
• Mission statement:
– Declares the business of the organization and its intended areas of
operations
– Explains what the organization does and for whom
– Example: Random Widget Works, Inc. designs and manufactures
quality widgets, associated equipment and supplies for use in modern
business environments
• Vision statement:
– Expresses what the organization wants to become
– Should be ambitious
– Example: Random Widget Works will be the preferred manufacturer of
choice for every business’s widget equipment needs, with an RWW
widget in every machine they use
Values statement
Ensuring that all users understand the security responsibilities and reward
excellent performance;
22
13 Storch Street T: +264 61 207 2258
Private Bag 13388 F: +264 61 207 9258
Windhoek E: [email protected]
NAMIBIA W: www.nust.na
Thank You.