customers or other external parties. Specialist advice from outside organizations may also be
needed. (NL ISO/IEC, 2010)
3. Security Management Planning
Security management planning ensures proper creation, implementation, and enforcement of a
security policy. The most effective way to tackle security management planning is to use a topdown approach. Upper, or senior, management is responsible for initiating and defining policies
for the organization. Security policies provide direction for all levels of the organization’s
hierarchy. It is the responsibility of middle management to flesh out the security policy into
standards, baselines, guidelines, and procedures. The operational managers or security
professionals must then implement the configurations prescribed in the security management
documentation. Finally, the end users must comply with all the security policies of the
organization.
Security management is a responsibility of upper management, not of the IT staff, and is
considered a business operations issue rather than an IT administration issue. The team or
department responsible for security within an organization should be autonomous. The
information security team should be led by a designated Chief Security Officer (CSO) who must
report directly to senior management. Placing the autonomy of the CSO and the CSO’s team
outside the typical hierarchical structure in an organization can improve security management
across the entire organization. It also helps to avoid cross -department and internal political
issues.
Elements of security management planning include defining security roles; prescribing how
security will be managed, who will be responsible for security, and how security will be tested
for effectiveness; developing security policies; performing risk analysis; and requiring se curity
education for employees. These efforts are guided through the development of management
plans.
The best security plan is useless without one key factor: approval by senior management.
Without senior management’s approval of and commitment to the security policy, the policy
will not succeed. It is the responsibility of the policy development team to educate senior
management sufficiently so it understands the risks, liabilities, and exposures that remain even
after security measures prescribed in the policy are deployed. Developing and implementing a
security policy is evidence of due care and due diligence on the part of senior management. If a
company does not practice due care and due diligence, managers can be held liable for
negligence and held accountable for both asset and financial losses.
A security management planning team should develop three types of plans:
Strategic plan: A strategic plan is a long-term plan that is fairly stable. It defines the
organization’s security purpose. It also helps to understand security function and align it
to goals, mission, and objectives of the organization. It’s useful for about five years if it is
Lebanese National Security Policy Guidelines v1.7
Page
11 |