Security 102: Information Security Plan Development

However, companies often do not match the level of protection with the data's actual value, this results in some information being over-protected and other highly valuable information not having adequate protection. To provide corporate information with the appropriate level of protection requires development, adoption and implementation of a plan to achieve this goal.

Steps for Developing a Plan
Organizations that recognize how they use and value information find the security planning process relatively easy, while those that do not and expect an "out of the box solution," find the process painful and are frequently exposed to uncomfortable realities. Five basic steps, listed below, can be helpful for developing an information security plan:
1. Identify the types of information that require protection
2. Estimate the value of information that exist in each type
3. Develop/Update an information security policy mandating that information be protected according to type
4. Set information protection standards for each information type
5. Create monitoring and management standards for checking compliance with the information protection standards

Risk Assessments: As organizations go through these steps, conducting risk assessments are essential for the following:

  • id
  • unit-1659132512259
  • type
  • Sponsored post