logo
Published on Isacaroma Newsletter (http://www.isacaroma.it/html/newsletter)

Information Security Governance: a call to action

By Agatino Grillo
Creato 2005-01-02 14:52
0412-securitygovernance The Corporate Governance Task Force was formed in December 2003 to develop and promote a coherent governance framework to drive implementation of effective information security programs.
Corporate governance consists of the set of policies and internal controls by which organizations, irrespective of size or form, are directed and managed. Information security governance is a subset of organizations’ overall governance program. Risk management, reporting, and accountability are central features of these policies and internal controls.
In this report, available in: http://www.cyberpartnership.org/InfoSecGov4_04.pdf [1], (477 K), F. William Conner, Chairman, CEO and President Entrust, Inc. and Arthur W. Coviello, CEO and President RSA Security Inc., provide a framework and guidelines to help organizations assess their performance and put in place an information security governance program.

The framework


The major elements of the ISG Framework include:

Annexes


To facilitate use of the framework, the Task Force has developed several additional tools:

 

Conclusions


Information security governance is not only a technical issue, but also a business and governance challenge that involves risk management, reporting, and accountability. Effective security requires the active engagement of executive management to assess emerging threats and provide strong cyber security leadership: the term penned to describe executive management’s engagement is corporate governance. Effective information security governance cannot be established overnight and requires continuous improvement.

 

The IT Governance Institute


from:
http://www.itgi.org [2]

The IT Governance Institute exists to assist enterprise leaders in their responsibility to ensure that IT is aligned with the business and delivers value, its performance is measured, its resources properly allocated and its risks mitigated.

ITGI has released its landmark IT Governance Global Status Report, covering IT governance perceptions and activities worldwide.
Download the executive summary (PDF, 193K):
http://www.itgi.org/TemplateRedirect.cfm?Template=/ContentManagement/ContentDisplay.cfm&ContentID=14539 [3]
 


Source URL:
http://www.isacaroma.it/html/newsletter/node/45