High Level View to Help Initiate a Security Management System
- This is a preview of the essay.
To view the full text you must login!
Background Information
This brief report aims to illustrate how, in my opinion, a company should start to tackle a security project whose main objective is to create the primary functions that should set the ball rolling towards the setting up of a security structure covering the whole company. (This assumes that the reader already has a significant level of awareness of the importance of security especially the way it enhances the value of the comapnuy's business assets and the potential damage that may result as a consequence of any security 'loop holes'.)
Since security processes cover all aspects of the company it is recommended that the project team be selected from key staff with expertise from the respective main areas. A sense of ownership must be sought from all team members and their respective staff/colleagues. This project is expected to bring about some very important and significant changes to our current systems. It is also a major challenge in bringing about a change in attitude towards security issues and helps develop a 'security aware culture'. A top management sponsor (ideally at board/exec. director level) must be identified and his appreciation of the importance of security must be unquestionable. Awareness at board level must be sought and planned in order to achieve the required level of authority.
Main Objectives
What to protect and How
The project team will first need to carry out an 'audit' exercise followed by risk analysis to determine what needs to be protected and how...