IT contributes to the company's businesses, and information security must meet the quality and safety requirements of these businesses. We need to establish a security indicator that is linked to the impact avoided (figure
4
); then, security will be legible and managed as a performance factor. Indeed, if the company is unaware of any "business" impact induced by IT, it may believe that the result would be the same without security, and that it would be a good idea to invest less in things that, after all, are restrictive.
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
This offer includes interactive articles. Their quizzes highlight the key information to remember and validate their acquisition: from reader to player, you can enrich your knowledge.
You can easily identify them thanks to this pictogram: