Governance and Information Security Management
摘要
Cybersecurity must be integrated in the governance and management of any organization. At the same time, there are several unique aspects of cybersecurity that require special competencies, which means that cybersecurity in many ways is a separate area within governance and management. Cybersecurity governance ensures that cybersecurity activities are aligned with business objectives, regulatory requirements, and ethical values. Information security management ensures that the organization has a systematic approach to protecting information assets from harm. It encompasses the policies, procedures, technologies, and practices that organizations implement to safeguard their information assets. In the end it is about managing cyber risks as part of enterprise risk management in general.