Home > Security Tips > Risk Management Strategies > Steps in the information security program life cycle
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

Steps in the information security program life cycle


Shon Harris
10.25.2006
Rating: -4.69- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This is the third article in the Information Security Governance Guide.

A information security program is the set of controls that an organization must govern. It is important to understand that a security program has a continuous life cycle that should be constantly evaluated and improved upon otherwise inconsistent efforts open the organization to increased risk.

There are different ways of describing a life cycle of any process. We will use the following steps: Many organizations do not follow a life cycle approach in developing, implementing and maintaining their information security management program. This is because they don't know how or feel as though this approach is cumbersome and a waste of time. The result of not following a life cycle structure usually results in:

Without applying a life cycle approach to a information security program and the security management that maintains the program, an organization is doomed to treating security as a project. Anything that is treated as a project has a start and stop date, and at the stop date everyone disperses to other projec



ts. Many organizations have good intentions in their security program kickoffs, but do not implement the proper structure to ensure that security management is an on-going and continually improving process. The result is a lot of starts and stops, and repetitive work that costs more than it should with diminishing results.

The main components of each phase are outlined below:

  • Implement
  • Implement solutions per program
  • Develop auditing and monitoring solutions per program
  • Establish goals and metrics per program
  • Operate and Maintain
  • Monitor and evaluate [IMAGE]

    About the author:
    Shon Harris is a CISSP, MCSE and President of Logical Security, a firm specializing in security educational and training tools. Shon is a former engineer in the Air Force's Information Warfare unit, a security consultant and an author. She has authored two best selling CISSP books, including CISSP All-in-One Exam Guide, and was a contributing author to the book Hacker's Challenge. Shon is also the co-author of Gray Hat Hacking: The Ethical Hacker's Handbook.

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Risk Management Strategies,   Information Security Policies, Procedures and Guidelines,   Information Security Management,   Security Awareness Training and Internal Threats,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Risk Management Strategies
    Cloud computing security: Choosing a VPN type to connect to the cloud
    Cloud computing security: Routing and DNS security threats
    Cloud computing security model overview: Network infrastructure issues
    How to align an information security framework to your business model
    When to use open source security tools over commercial products
    Vulnerability test methods for application security assessments
    Security book chapter: Applied Security Visualization
    The 100-day plan: Achieving success as a new security manager
    Recovering stolen laptops one step at a time
    How to get information security buy-in from the executive team

    Information Security Policies, Procedures and Guidelines
    Cybersecurity czar candidate questions clout of new position
    Incident response planning
    The basics of enterprise GRC project management
    RSA council addresses growing security risks in the cloud
    How to write a risk methodology that blends business, security needs
    Risk management must include physical-logical security convergence
    DHS fills National Cybersecurity Center post
    New partnerships, creative thinking help security bust recession
    Experts optimistic of Obama cybersecurity plan
    WH cybersecurity plan needs private sector guidance

    Security Awareness Training and Internal Threats
    Social engineering training could disrupt botnet growth
    How to write a risk methodology that blends business, security needs
    Risk management must include physical-logical security convergence
    Tabletop exercises sharpen security and business continuity
    Security policies need simplifying, expert says
    Microsoft IE 8 security only benefits educated users
    Security book chapter: The Truth About Identity Theft
    How to integrate the security of both physical and virtual machines
    Laid off workers likely to steal company data, survey warns
    Information security book excerpts and reviews

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    defense in depth  (SearchSecurity.com)
    non-disclosure agreement  (SearchSecurity.com)
    security policy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Research Solutions for Network Security, Access Control and Security Threats
    More Security Resources for Resellers, VARs and OEMs
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts