

|
An
effective IT security program
should encompass
multiple layers of protection. An organization should
evaluate the value and criticality of its information
systems and determine the security controls that are
appropriate to the level of risk. A security program,
whether at the organizational or individual system level,
should include an appropriate mixture of security controls:
management, operational, and technical. Reliance on
technical resources alone will be insufficient without
complementary management or operational controls.
An IT security
program is a set of security controls, which can be grouped
under the terms management, operational, and technical.
We can assist
organization decision makers in developing and maintaining
an organization-wide security program, helping to ensure
effective implementation of the program, evaluate the
performance of major organization components, and provide
appropriate security training of organization employees with
significant security responsibilities. TWe can also perform
independent evaluations and audits of an organization IT
security program. |
 |