261inforMation seCurity
Business continuity management—planning for natural and
man-made disasters and recovering from them.
Compliance—involves complying with any applicable regulatory
and legal requirements, such as HIPAA, Gramm–Leach–
Bliley Act, and cryptography export controls.
Board and management have several fundamental responsibilities
to ensure that information security is appropriately enforced. ey
should understand why information security needstobe placed at
the highest preference. e impacts are
• Risks and threats are real and could have significant impact
on the enterprise.
• Effective information security requires coordinated and inte-
grated action from the top to bottom.
• IT investments can be very substantial and easily misd ...