Lecture 4
Security Governance Concepts, Principles, and Policies Understand and align security function to goals, mission, and objectives of the organization Understand and apply security governance Understand and apply concepts of confidentiality, integrity and availability Develop and implement security policy Manage the information life cycle (classification, categorization and ownership) Objectives: Security Management Planning Security management planning ensures proper creation, implementation, and enforcement of a security policy. Upper/Senior, management is responsible for initiating and defining policies for the organization. Security policies provide direction for all levels of the organization’s hierarchy. It is the responsibility of middle management to flesh out the security policy into standards, baselines, guidelines, and procedures. The operational managers or security professionals must then implement the configurations prescribed in the security management documentation. Finally, the end users must comply with all the security policies of the organization.