CHAPTER 3

Security Program Management and Operations

This chapter discusses the following topics:

•  Security program management

•  Security program budgets, finance, and cost control

•  Security program resource management: building the security team

•  Project management

The CISO carries out the job of protecting the organization’s assets by implementing a well-planned and executed information security program. This chapter describes what an effective information security program looks like and how it is managed, staffed, and funded. An information security program generally has two types of activities: subprograms, also known as streams of work, which are long-term activities or ongoing activities, and security projects, which have ...

Get CCISO Certified Chief Information Security Officer All-in-One Exam Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.