Introduction

He that would govern others, first should be the master of himself.

Phillip Massinger, 1583–1640

Information security as a technical practice has been around long enough that some individuals have retired from an entire career focused on information security. As a career path with multiple disciplines as part of a profession, information security has only gained real traction over the past 10 to 15 years. In fact, many of the laws, regulations, standards, and control frameworks driving how information security controls are implemented have been promulgated in the new millennium.

Security incidents have prompted companies to implement controls in a reactive nature, without the benefit of a planned governance framework to guide ...

Get Information Security Governance Simplified now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.