SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

FCS security governance critical success factor

  Quote
Guest
Guest user Created:   Nov 05, 2020 Last commented:   Nov 05, 2020

FCS security governance critical success factor

What measure indicate me a risk of failure on governance ISMS , for example
The number of communications from board of directors relating to information security or % of board meetings that did not address security issues
what else can i indicate , thank you

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Nov 05, 2020

Considering ISO 27014, the ISO standard for Governance of Information Security, the governance of information security is a system for control and direction of information security activities.

Considering that, examples of measurements to identify failure to control and direct information security activities are:

  • low number of business strategies supported by information security initiatives
  • low number of controls achieving proposed objectives
  • high number of information security incidents
  • no achievement of proposed objectives for the ISMS

The measurements you proposed are mainly focused on management activities, and these cannot ensure the expected results for information security are achieved (e.g., all meetings can address security issues, but no one of them is effectively resolved over time).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 05, 2020

Nov 05, 2020

Suggested Topics