Publication Cover
EDPACS
The EDP Audit, Control, and Security Newsletter
Volume 31, 2003 - Issue 6
159
Views
4
CrossRef citations to date
0
Altmetric
Original Articles

Information Security Governance Reporting

&
 

Abstract

Imagine you are the Chief Information Security Officer (CISO) and your boss, the CIO or CEO, is asking some simple questions: “How secure are our information systems? Is security getting better or worse? How do you know that?” You could describe the successful installation of the newest firewalls, the performance of the intrusion detection systems, the centralized deployment of up-to-date antivirus solutions, the application of software patches on all network devices, and the popularity of your security awareness program. But that is not an answer to the questions. Your boss wants to know not only what you have done to lower the risk, but also how effective you have been. It is all about process, metrics, and trend monitoring. and money, of course!

Reprints and Corporate Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

To request a reprint or corporate permissions for this article, please click on the relevant link below:

Academic Permissions

Please note: Selecting permissions does not provide access to the full text of the article, please see our help page How do I view content?

Obtain permissions instantly via Rightslink by clicking on the button below:

If you are unable to obtain permissions via Rightslink, please complete and submit this Permissions form. For more information, please visit our Permissions help page.