1.1 Establish security’s role in organizational culture, vision and missionÂ
» Define information security program vision and missionÂ
» Align security with organizational goals, objectives and valuesÂ
» Define security’s relationship to the overall business processesÂ
» Define the relationship between organizational culture and securityÂ
1.2 Align security program with organizational governanceÂ
» Identify and navigate organizational governance structureÂ
» Validate roles of key stakeholdersÂ
» Validate sources and boundaries of authorizationÂ
» Advocate and obtain organizational support for security initiativesÂ
1.3 Define and implement information security strategiesÂ
» Identify security requirements from business initiativesÂ
» Evaluate capacity and capability to implement security strategiesÂ
» Manage implementation of security strategiesÂ
» Review and maintain security strategiesÂ
» Prescribe security architecture and engineering theories, concepts and methodsÂ
1.4 Define and maintain security policy framework Determine applicable external standardsÂ
» Determine applicable external standardsÂ
» Determine data classification and protection requirementsÂ
» Establish internal policiesÂ
» Advocate and obtain organizational support for policiesÂ
» Develop procedures, standards, guidelines and baselinesÂ
» Ensure periodic review of security policy frameworkÂ
1.5 Manage security requirements in contracts and agreementsÂ
» Evaluate service management agreements (e.g., risk, financial) Â
» Govern managed services (e.g., infrastructure, cloud services) Â
» Manage impact of organizational change (e.g., mergers and acquisitions, outsourcing)Â
» Ensure that appropriate regulatory compliance statements and requirements are included in contractual agreements Â
» Monitor and enforce compliance with contractual agreementsÂ
1.6 Manage security awareness and training programs Â
» Promote security programs to key stakeholders Â
» Identify needs and implement training programs by target segment Â
» Monitor and report on effectiveness of security awareness and training programs Â
1.7 Define, measure and report security metrics Â
» Identify Key Performance Indicators (KPI) Â
» Associate Key Performance Indicators (KPI) to the risk posture of the organization Â
» Use metrics to drive security program development and operationsÂ
1.8 Prepare, obtain and administer security budget Â
» Prepare and secure annual budget Â
» Adjust budget based on evolving risks and threat landscape Â
» Manage and report financial responsibilitiesÂ
1.9 Manage security programsÂ
» Define roles and responsibilities Â
» Determine and manage team accountability Â
» Build cross-functional relationships Â
» Resolve conflicts between security and other stakeholdersÂ
» Identify communication bottlenecks and barriers Â
» Integrate security controls into human resources processesÂ
1.10 Apply product development and project management principles Â
» Incorporate security into project lifecycle Â
» Identify and apply appropriate project management methodology Â
» Analyze project time, scope and cost relationship