A. OVERVIEW Information security is not only a technical issue, but also a business and governance challenge that involves risk management, reporting, and accountability. It is a top-down process requiring a comprehensive information security strategy that is explicitly linked to the organization’s business processes and objectives. Effective security requires the active engagement of executive management to address emerging threats and provide strong cyber security leadership. The term used to describe executive management’s engagement is Information Security Governance. Information Security Governance consists of the set of policies and internal controls by which information security activities within an organization, irrespective of size or form, are directed and managed. Risk management, reporting, and accountability are core focus area of all information security policies and internal controls. Information security governance is a subset of an organization’s overall corporate governance programme. For security to be effective, it must be included in all organizational and business processes from end to end - physical, operational and technical. A formal information security strategy must be implemented by developing comprehensive information security policies consistent with the goals and mission of the organization. To provide effective governance, a set of enterprise standards for each policy must be developed to provide defined boundaries for acceptable processes and procedures. Education, training and awareness must also be considered to convey information to all personnel as part of an ongoing process to change behaviours not conducive to secure, reliable operations. The strategy must then be implemented through a comprehensive information security programme that includes wellconceived and complete policies and standards. NATIONAL INFORMATION ASSURANCE MANUAL 14

Select target paragraph3