Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Governing for Enterprise Security Implementation Guide

0

Created on: Jul 27, 2009 12:50 PM by SEI - Last Modified:  Jul 29, 2009 11:29 AM by SEI

This guide is designed to help business leaders implement an effective program to govern information technology (IT) and information security. Our objective is to help you make well-informed decisions about many important components of GES such as adjusting organizational structure, designating roles and responsibilities, allocating resources (including security investments), managing risks, measuring results, and gauging the adequacy of security audits and reviews. The intent in elevating security to a governance-level concern is to foster attentive, security-conscious leaders who are better positioned to protect an organization’s digital assets, its operations, its market position, and its reputation.

Be forewarned - security is a relatively new area of governance for most organizations. It can be complicated for newcomers to IT and information security. Although the U.S. government has encouraged executives to take a more active role, many still do not understand that security requires action at the governance level. Based on organizations’ growing dependence on IT and IT-based controls, information and IT security risks increasingly contribute to operational and reputational risk. Leaders must understand the legal, technical, managerial, and operational considerations that converge in an enterprise security program (ESP). Reading short executive summaries will not suffice. As with audit and compliance responsibilities, boards and senior officers need to thoroughly understand effective enterprise security governance and how to bring it about. For instance, beyond comprehending organizational structure, roles, and responsibilities, leaders need to understand the more detailed responsibilities and tasks required to develop and operate a sustainable security program. Tackling GES is complex, and requires learning information and gaining knowledge that is missing in many organizations today.

The GES Implementation Guide, uploaded by the Software Engineering Institute, provides such guidance by providing a roadmap that describes actions, roles and responsibilities, and documented outcomes that occur at each step in the roadmap.

The attached Zip file includes:

• Intro Page.doc

• Cover Sheet and Terms.pdf

• Governing for Enterprise Security Implementation Guide.pdf

Related Knowledge Network Content

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

Budget & Finance Toolkit for IT - 2010 Edition

Download a comprehensive collection of templates, forms, instruction and advice that will help you to plan and submit your 2010 IT Budget.

Learn more >

Windows 7 Upgrade Project Kit

Moving to Windows 7? The Windows 7 Upgrade Project Kit is the ideal support tool for managing all phases of an organizational upgrade to Windows 7. The tools and templates in this kit will help you develop a strategy and map out the implementation tactics which link your Windows 7 deployment to your company's bottom line.

Learn more >

Compliance and Risk Mitigation

Compliance and risk mitigation solutions that strengthen data security, automate compliance measures, and reduce TCO for a more viable business future.

Data Warehousing for Business Intelligence

Comprehensive storage solutions for better data access and retrieval, leading to better-informed business decisions.

Business Intelligence

Best-practice tools, strategies and technologies for determining and managing the data you need to make better business decisions.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

A Complete View of the Enterprise: Linking Operational and Financial Planning in Global Organizations

Read this white paper from CFO Research Services that examines why and how chief financial officers are looking to create "highly integrated" organizations by moving from standalone spreadsheets to integrated planning, budgeting, and forecasting systems.

Preventing Data Corruption in the Event of an Extended Power Outage

This white paper discusses various power management software configurations, and presents best practices aimed at ensuring system uptime.