T he initial step in the IT security management process comprises an examination of the organization’s IT security objectives, strategies, and policies in the context of the organization’s general risk profile. This can only occur in the context of the wider organizational objectives and policies, as part of the management of the organization. Organizational security objectives identify what IT security outcomes should be achieved. They need to address individual rights, legal requirements, and standards imposed on the organization, in support of the overall organizational objectives. Organizational security strategies identify how these objectives can be met. 1
đang được dịch, vui lòng đợi..
