1.2.1 Alignment of security function to business strategy, goals, mission, and objectives
Security Management planning aligns the security functions to the strategy, goals, mission, and objectives of the organization. This includes designing and implementing security based on business cases, budget restriction, or scarcity of resources.
A business case is usually a documented argument or stated position in order to define a need to make a decision or take some form of action and is often made to justify the start of a new project.
Security can be expensive but is most often less costly than the absence of that security. Thus, security becomes an essential element of reliable and long-term business operation.
The top-down approach is an effective way to tackle security management, where upper or senior management is responsible for initiating and defining policies for the organization.
Security policies provide direction for all levels of the organizations' hierarchy. It is responsible for initiating and defining policies for the organization.
Security policies provide direction for all levels of the organization's hierarchy. It is the responsibility of middle management to flesh out the security policy into standards, baselines, guidelines and procedures. The operational managers or security professionals must then implement the configurations prescribed in the security management documentation. Finally, the end users must comply with all the security policies of the organization.
The opposite of the top-down approach is the bottom-up approach, where the IT staff makes security decisions directly without input from senior management. This approach is rarely used in IT industry.
Security management is a responsibility of upper management, not of the IT staff, and is considered an issue of business operations rather than IT administration.
The Security management/information security (InforSec) team or department responsible for security within an organization and should be autonomous and outside the typical hierarchical structure in an organization. It is led by designated chief information security officer (CISO) who must report directly to senior management.
CISO is also helping to avoid cross-department and internal political issues.
Elements of security management planning include
Elements of security management planning include
- Defining security roles;
- Prescribing how security will be managed,
- Who will be responsible for security,
- How security will be tested for effectiveness;
- Developing security policies;
- Performing risk analysis; and
- Requiring security education for employees.
These efforts are guided through the development of management plans, by approved by senior management.
It is the responsibility of policy development team to educate senior management to make understand the risks liabilities and security measures prescribed in the policy are deployed.
It is the role of senior management for developing and implementing a security policy, managers can be held liable for negligence and held accountable for both asset and financial losses.
A security management planning team should develop three types of plans.
Strategic Plan :
- It is long term stable plan
- Defines organizations security purpose
- Helps to understand security function and align it to the goals, mission and objective of the organization.
- It serves as the planning horizon.
- Long term goals and visions for the future are discussed.
- It include a risk assessment.
Tactical Plan
- It is a midterm plan developed to provide more detail on accomplishing the goals set forth in the strategic plan or can be crafted adhoc based on unpredictable events.
- It is useful for about a year.
- Often prescribes and schedules the tasks necessary to accomplish organizational goals.
- Example: Project plans, Acquisition Plans, Hiring Plans, Budget Plans, Maintenance Plans, Support Plans, and System development Plans.
Operational Plan
- It is short term, highly detailed plan based on the strategic and tactical plans.
- It is valid and useful only for a short time.
- It is updated often to retain compliance with tactical plans
- It define how to accomplish various goals of the organization, It include resource allotment, budgetary requirements, staffing assignments, scheduling, and step-by-step or implementation procedure.
- Operational plan include details on how the implementation process are in compliance with the organization security policy.
- Example : Training Plans, System Deployment Plans and Product design plans.
Security is a continuous process. Effective security plans focus attention on specific achievable objectives, anticipate change and potential problems, and serve as a basis for decision making for the entire organization.
The security documentation should be concrete, well defined and clearly stated, it must be maintained, and to be used.
The security documentation should be concrete, well defined and clearly stated, it must be maintained, and to be used.

0 Comments