Does the information security program have a charter that clearly defines the information security program's role within the organization?
- This is the document that establishes the authority of the information security program. If it does not exist, it must be created.
- It needs to be presented and agreed upon by your organization's executive team.
- It should be signed by a current executive within the organization. This individual should have significant authority across the entire organization.
Foundational information security activities (cyber/IT hygiene):
- Discover assets: Determine what assets are on your network
- Secure configurations: Implement best practice security
- Restrict privileges ...