1. Get executive commitment to a security charter with a principle for each of the ten ISO 27002 domains and appoint yourself to act on behalf of the executives in accordance with charter.
2. Do a sing and dance you have cracked the hardest piece of the puzzle
3. Write up security governance docs to establish an Information Security Management System (include exemption management, metrics, compliance testing, sanctions for non-compliance and a document map)
4. Create draft security policy statements for the key security policies
5. Workshop draft policies with anyone who will listen (HR, IT ops, IT architecture, risk, internal audit etc.)
6. Record and refine stakeholder input (and put in version history of docs)
7. Issue security policies as draft for comment on Intranet
8. Take in feedback and refine (if any)
9. Get security policies endorsed
10. draft security standards and include KPIs
11. workshop with stakeholders
12. refine
13. issue as draft
14. get endorsed
15. execute security awareness campaign
16. write processes
17. write procedures
18. write baselines and use these to guide construction of SOEs
About Me
- Matthew Hackling
- Matt runs his own security consultancy called Ronin Security. His focus is information security management and he has a keen interest in infrastructure and web application security. He's a CISSP and the current Branch Executive of the Melbourne chapter of the Australian Information Security Association.
Blog Archive
-
▼
2008
(24)
-
▼
September
(13)
- Good security awareness program at the royal show
- Mobile phone products to invent
- How to raise the profile of your information secur...
- First jobs
- info-sec car analogies
- challenges with vulnerability management
- The simple things in inosec are often the most eff...
- Former federal privacy commissioner addressing AIS...
- my first security haiku
- Security governance - launching the offensive
- Security Governance: The First battle
- Security governance: The Initial Skirmish
- Reflections on the Australian Infosec market
-
▼
September
(13)
Labels
- AISA (1)
- australian information security market (1)
- career advice (1)
- causes (1)
- DoS (1)
- economics (1)
- FUD (1)
- futurism (1)
- information security governance (4)
- IPS (1)
- privacy (2)
- sacred cows (1)
- security patching (1)
- vulnerability management (1)
- webappsec (1)
Wednesday, September 3, 2008
Subscribe to:
Post Comments (Atom)
Handy Links
Matt's list of blogs
-
-
-
TEDxMaui -- Hack Yourself First3 weeks ago
-
-
-
FedRAMP: It’s Here but Not Yet Here2 months ago
-
Bunraku V0.0.36 months ago
-
GoGrid Security Breach10 months ago
0 comments:
Post a Comment