EISA/information security management programs
Enterprise information security architecture
- refers to a group of requirements, processes, principles, and models that regulate an organization’s structure and behavior in terms of system security, processes, and employees.
An information security management program is an organization-wide initiative to develop and maintain a secure environment.
Enterprise Information Security Architecture Goals
1st) Real time monitoring of the organization’s network
2nd) Detection and recovery from security breaches
- First thing: you’ll have to assume that at some point, the system WILL be breached. No matter the amount of time and resources put into the security of a system, it is always going to be somewhat unreasonable to expect that nothing has the capability, along with the motivation to break into that system. Now, knowing this, you will have to come up w/ certain plans of action in order to be able to properly respond to breaches more easily (“recovery from security breaches”).
3rd) Ensuring cost efficiency of security provisions
4th) Helping the IT departments to function properly
- One of the very best ways to help the IT departments to function more efficiently would be to create a compatible environment (an environment where they have consistent access to the sort of information they need to do their jobs) and a structure for which they could follow on a consistent basis (when x happens, react with protocol y). All the items represented in this list, when put into actual practice, will help the IT departments in one way or another.
5th) Helping in the process of risk assessment of IT assets
- Sort of relating back to what was said in “Ensuring cost efficiency of security provisions”; This comes down to estimating the value of specific information/data and deciding where that particular piece of information/data lies in terms of security priority.