
1.10 The Security Process Cycle
Figure 11. The Security Process Cycle
Key Points
In order to implement an effective security policy, an enterprise must establish
an ongoing security process cycle of risk analysis, policy definition,
implementation, administration and audit.
Presentation Script
The process of securing an information system is a cyclical, on-going effort with
involvement from all levels of the corporation, from the highest level of
management down to the end users and programmers. There are five primary
stages in the security process cycle, as depicted in Figure 11.
•
Risk Management:
Risk management is the process that studies the potential ...