The 10 deadly sins of information security
What are the most made mistakes when we are talking about information security? If you have any more suggestion, please let us know!
- Not realizing that information security is a corporate governance responsibility (the buck stops right at the top).
- Not realizing that information security is a business issue and not a technical issue.
- Not realizing the fact that information security governance is a multi-dimensional discipline.
- (information security governance is a complex issue, and there is no silver bullet or single ‘off the shelf’ solution).
- Not realizing that an information security plan must be based on identified risks.
- Not realizing the important role of international best practices for information security management.
- Not realizing that a corporate information security policy is absolutely essential.
- Not realizing that information security compliance enforcement and monitoring is absolutely essential.
- Not realizing that a proper information security governance structure (organization) is absolutely essential.
- Not realizing the core importance of information security awareness amongst users.
- Not empowering information security managers with the infrastructure, tools and supporting mechanisms to properly perform their responsibilities.