So you want to conduct a symphony of information security within your organisation? Well what are the instruments you will use in your orchestra? I suggest you might want to look for or plan the creation of the following:
- audit issue register (lead violin, sometimes a bit too screechy)
- enterprise risk register
- significant business unit risk registers
- compliance requirement register ( the timpani )
- mapping of compliance requirements to your Information Security Management System
- control testing Management reports and database
- management reporting template
- existing enterprise security plan and perhaps security plans of significant business units
- list of business units by criticality
- list of business processes by criticality within business units
- list of business applications by criticality with function descriptions
- current security budget
- business case template and submission procedures
- document map of ISMS with status of documents within it (approved, under review, drafted, not started)
- organisation chart
- list of security projects with budget and status
- list of business projects by criticality to business success
- enterprise security architecture ( well at least the "zone model" with zones mapped to examples in the existing environment )
- data classification scheme
About Me
- Matthew Hackling
- Matt runs his own security consultancy called Ronin Security. His focus is information security management and he has a keen interest in infrastructure and web application security. He's a CISSP and the current Branch Executive of the Melbourne chapter of the Australian Information Security Association.
Blog Archive
Labels
- AISA (1)
- australian information security market (1)
- career advice (1)
- causes (1)
- DoS (1)
- economics (1)
- FUD (1)
- futurism (1)
- information security governance (4)
- IPS (1)
- privacy (2)
- sacred cows (1)
- security patching (1)
- vulnerability management (1)
- webappsec (1)
Monday, May 3, 2010
Subscribe to:
Post Comments (Atom)
Handy Links
Matt's list of blogs
-
-
-
TEDxMaui -- Hack Yourself First3 weeks ago
-
-
-
FedRAMP: It’s Here but Not Yet Here2 months ago
-
Bunraku V0.0.36 months ago
-
GoGrid Security Breach10 months ago
1 comments:
I'd add "delegation(s) of authority" which will allow decisive sanctioned action when you need to pull the plug on something to contain a problem. And the Business Continuity Plan (at least your section of it!).
Post a Comment