Security is a business operations issue. Security is an organizational process, not just something
the IT geeks do behind the scenes. Using the term security governance is an attempt to
emphasize this point by indicating that security needs to be managed and governed throughout
the organization, not just in the IT department.
Security governance needs to address every aspect of an organization. This includes
acquisitions, divestitures, and governance committees. Acquisitions and mergers place an
organization at an increased level of risk. Such risks include inappropriate information
disclosure, data loss, downtime, or failure to achieve sufficient return on investment (ROI).
Similarly, a divestiture or any form of asset or employee reduction is another time period of
increased risk and thus increased need for focused security governance. Often, security
governance is managed by a governance committee or at least a board of directors. This is the
group of influential knowledge experts whose primary task is to oversee and guide the actions
of security and operations for an organization. (Stewart et al., 2004)
5. Security Management Concepts and Principles
Security management concepts and principles are inherent elements in a security policy and
solution deployment. They define the basic parameters needed for a secure environment. They
also define the goals and objectives that both policy designers and system implementers must
achieve to create a secure solution. It is important for real-world security professionals to
understand these items thoroughly.
The primary goals and objectives of security are contained within the CIA Triad, which is the
name given to the three primary security principles:
Confidentiality
Integrity
Availability
Security controls are typically evaluated on how well they address these core information
security tenets. Overall, a complete security solution should adequately address each of these
tenets. Vulnerabilities and risks are also evaluated based on the threat they pose against one or
more of the CIA Triad principles. Thus, it is a good idea to be familiar with these principles and
use them as guidelines for judging all things related to security.
These three principles are considered the most important within the realm of security.
However important each specific principle is to a specific organization depends on the
organization’s security goals and requirements and on the extent to which the organization’s
security might be threatened. (Stewart et al., 2004)
Lebanese National Security Policy Guidelines v1.7
Page
13 |