|
An Introduction To |
|
Internal organisationObjective: To manage information security within the organisation. A management framework should be established to initiate and control the implementation of information security within the organisation. Management commitment to information securityManagement should actively support security within the organisation through clear direction, demonstrated commitment, explicit assignment and acknowledgement of information security responsibilities. Information security co-ordinationIn a large organisation it might be necessary to co-ordinate information security measures through a cross-functional forum. Allocation of information security responsibilities Responsibilities for the protection of individual assets and for carrying out specific security processes should be explicitly defined. Authorisation process for information processing facilitiesInstallation of information processing facilities should be technically approved and authorised. Specialist information security adviceSpecialist advice on information security may be required. Confidentiality agreementUsers of organisational IT facilities and organisational information should sign a confidentiality undertaking either as part of their employment contract or as a separate agreement before access to information processing systems. Contact with authoritiesContacts with relevant authorities should be maintained to co-operate to combat general security threats. Contact with special interest groupsContacts with security specialists and special interest groups should be maintained to co-operate to combat general security threats. Independent review of information securityImplementation of information security should be independently reviewed. |
The Security Practitioner An Introduction to Information Security |