W IKEPEDI A Governance  makes decisions that define expectations, grant  power , or verify  performance . It consists either of a separate process or  of a specific part of  management  or  leadership  processes.   Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007
Drivers sox, basel II, national legislation, IT accountability, risk mitigation Derivatives IT management framework, provisioning framework, information security framework   Direction unified management systems  standards PAS99 & other initiatives Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 IT governance
Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 advantages of a governance framework? No reinvention required Excellent signposting tool Encapsulates best practices Knowledge sharing Auditable
Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Management cycle from 4 different governance frameworks Governance frameworks
Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 The impact of governance on information
Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 The impact of internal & external influences on information
Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 The impact of internal & external influences on information
Security Governance as a model for the management of corporate information Taken from the ISO Guide 72 on justification and drafting of management system standards,  http://www.tc176.org/PDF/News_Articles/2002/2002_7.pdf Security Risk Management Australasia 2007
ISO/IEC27001 ACSI33 ISF – Best Practices ISM3 Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Some leading frameworks
Cybercrime Act 2001 Information Confidentiality Telecommunications act 1997 Tax act 1999 Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Legislation
Governance & the advantages of a framework We discussed the various IT governance frameworks and the commonalities between frameworks  We then looked at information security and the different types of Information security governance frameworks available and  the impact standards and legislation had on corporate information Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Summary
Questions? Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007

Security Governance

  • 1.
    W IKEPEDI AGovernance makes decisions that define expectations, grant power , or verify performance . It consists either of a separate process or of a specific part of management or leadership processes. Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007
  • 2.
    Drivers sox, baselII, national legislation, IT accountability, risk mitigation Derivatives IT management framework, provisioning framework, information security framework Direction unified management systems standards PAS99 & other initiatives Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 IT governance
  • 3.
    Security Governance asa model for the management of corporate information Security Risk Management Australasia 2007 advantages of a governance framework? No reinvention required Excellent signposting tool Encapsulates best practices Knowledge sharing Auditable
  • 4.
    Security Governance asa model for the management of corporate information Security Risk Management Australasia 2007 Management cycle from 4 different governance frameworks Governance frameworks
  • 5.
    Security Governance asa model for the management of corporate information Security Risk Management Australasia 2007 The impact of governance on information
  • 6.
    Security Governance asa model for the management of corporate information Security Risk Management Australasia 2007 The impact of internal & external influences on information
  • 7.
    Security Governance asa model for the management of corporate information Security Risk Management Australasia 2007 The impact of internal & external influences on information
  • 8.
    Security Governance asa model for the management of corporate information Taken from the ISO Guide 72 on justification and drafting of management system standards, http://www.tc176.org/PDF/News_Articles/2002/2002_7.pdf Security Risk Management Australasia 2007
  • 9.
    ISO/IEC27001 ACSI33 ISF– Best Practices ISM3 Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Some leading frameworks
  • 10.
    Cybercrime Act 2001Information Confidentiality Telecommunications act 1997 Tax act 1999 Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Legislation
  • 11.
    Governance & theadvantages of a framework We discussed the various IT governance frameworks and the commonalities between frameworks We then looked at information security and the different types of Information security governance frameworks available and the impact standards and legislation had on corporate information Security Governance as a model for the management of corporate information Security Risk Management Australasia 2007 Summary
  • 12.
    Questions? Security Governanceas a model for the management of corporate information Security Risk Management Australasia 2007