Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Effective information security governance: executive support a must

By Fernando Monteleone on July 2, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

According to a very recent report by the Identity Theft Resource Center, the first half of 2015 alone saw 400 publicized security breaches with over 117 million records exposed. While most organization have ongoing initiatives to keep their names off the list, many are misguided in their approach – making the effort almost entirely an IT project.

Numerous studies show a direct correlation between the maturity of an organization’s security profile and the level of engagement and understanding by its board and/or executive management. The IT Governance Institute in its Board Briefing on IT Governance, 2nd Edition, states: “Security governance is the set of responsibilities and practices exercised by the board and executive management with the goal of providing strategic direction, ensuring that objectives are achieved, ascertaining that risks are managed appropriately and verifying that the enterprise’s resources are used responsibly.”

In comparing the critical differences with respect to the effectiveness of a company’s information security governance program, published author, Shon Harris, highlights the following distinctions common to successful organizations:

  1. Board members understand that information security is critical to the company and requires regular updates on performance and security incidents
  2. The officers and business unit managers participate in a risk management committee that meets regularly on the topic of information security
  3. Executive management sets acceptable risk levels which are the basis for the company’s security policies and related practices
  4. Executive management holds business unit managers responsible for carrying out risk management activities for their specific business units
  5. Critical business processes are documented along with the risks that are inherent in the different steps within the business processes
  6. Employees are held accountable for any security breaches they participate in, either maliciously or accidentally
  7. Security products, managed services and consultants are purchased and deployed in an informed manner and are regularly reviewed
  8. The organization regularly reviews its business and security processes with the goal of continuous improvement

Engaging the C-Suite and board in the complexities and efforts of the entire organization, including IT is critical to managing an effective risk management program.

Photo of Fernando Monteleone Fernando Monteleone
Read more about Fernando MonteleoneEmail
  • Posted in:
    Other, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo