1. Principles to avoid mistakes
One of the key organizational principles for information systems security is to have a dedicated ICT (information and communication technologies) risk management framework, a dedicated audit and testing plan, and a specific training and awareness program. This also takes into account the need to monitor risks via a dedicated dashboard. Figure
1
illustrates these principles, which concern the implementation of a global governance framework for the management of risks linked to information and communication technologies (ICT), the implementation of a dashboard enabling regular monitoring of these risks, the implementation and monitoring of information system security audit tests, and the monitoring of employee training in information security issues.
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
Principles to avoid mistakes