Thursday, 6 September 2012

Information Security: concepts

In considering how Information Security can be effectively deployed within an organisation, the attitude of both the organisation and the information security need to be correct. There are some basic concepts about the effective deployment that need to be considered by those involved with information security.
  1. Effective information security needs to be part of the culture of the organisation, sponsored and supported by the senior management team, who need to lead and show by example support for the information security policies and the information security management system (ISMS).
  2. Effective information security needs to be enabler of the organisations goals and also enable the employees to go about their task with no or little hindrance. 
  3. Effective information security will be an evolving process, it will need to take into account changes in the environment. It needs to constantly aligned with the organisations aims and goals, it should adapt to changes in the organisation, it needs to reflect changes in the value of information it is protected and take into account changes in technology.
  4. Effective information security will be cost effective and provide a return on investment, it can be a cost saver by reducing the impact of incidents and disaster, by reducing the likelihood of the organisation failing to meet legal, regulatory and compliance requirements.
Information security is a lifecycle, it is often described as using the Deming cycle.
  • Plan
  • Do
  • Check
  • Act
An effective ISMS will be regular reviewed to ensure that it remains effective and gives benefit to the organisation. As part of this review process its alignment with the organisations goal and aims will be checked and if necessary changes made. The organisational aims and goal will be set by the senior management team of the organisation and these outline how the organisation will conduct its business, where it wants to be and how it will get there.

For an ISMS to be effective and enable the organisations to achieve its goals and aims, the operation of organisation must be fully understood by those in Information Security. Professionalism will require that in for us to put in place an effective ISMS we should understand what we are trying to achieve, which is not only the protections of the organisations assets but also enabling the organisation to be successful and achieve its goals and aims.

No comments:

Post a Comment