Security Management
Improving Security Management.
How to improve your organisation's Information Security Management Practices is the topic of this section of the Security Governance web site. We will suggest a new approach to security management based on what we learned from management practices in High Reliable Organisations: Organisations that have been capable of providing high levels of safety in a complex and unsafe environment. Applying similar management practices to Information security management is unavoidable as the security environment keeps on increasing in complexity and insecurity.
While in the traditional approach to information security the emphasis is on planning, information security in the 21st century will depend on observing the security environment of your organisation. In my view, you will never be secure if you cannot detect small security incidents and learn from them. This section will therefore revisit decison making models in information security and propose the use of a better model based on OODA.