
1
Chapter 2
Organization of
Information Security
Patrick D. Howard
e sixth clause of ISO 27002 focuses on the information security responsibili-
ties of management within an organization. Specifically, it emphasizes the neces-
sity of management commitment to the security of the organization’s information
resources. e importance of this topic is revealed in a cursory review of the 10 crit-
ical success factors identified in ISO 27002. Organizing for information security is
Contents
e Internal Information Security Organization .................................................. 18
Management Support .......................................................................................... ...