05_PS4_KeySuccessFactors

Research/Information for Key Success Factors:

Critical success factors for Info Security Management Systems
To be effective, the ISMS must:[|[][|4][|]]
 * have the continuous, unshakeable and visible support and commitment of the organization’s top management;
 * be managed centrally, based on a common strategy and policy across the entire organization;
 * be an integral part of the overall management of the organization related to and reflecting the organization’s approach to Risk Management, the control objectives and controls and the degree of assurance required;
 * have security objectives and activities be based on business objectives and requirements and led by business management;
 * undertake only necessary tasks and avoiding over-control and waste of valuable resources;
 * fully comply with the organization philosophy and mindset by providing a system that instead of preventing people from doing what they are employed to do, it will enable them to do it in control and demonstrate their fulfilled accountabilities;
 * be based on continuous training and awareness of staff and avoid the use of disciplinary measures and “police” or “military” practices;
 * be a never ending process;

What are the critical success factors?
Experience has shown that the following factors are often critical to the successful implementation of information security within an organization:
 * security policy, objectives and activities that reflect business objectives;
 * an approach to implementing security that is consistent with the organizational culture;
 * visible support and commitment from management
 * a good understanding of the security requirements, risk assessment and risk management
 * effective marketing of security to all managers and employees;
 * distribution of guidance on information security policy and standards to all employees and contractors;
 * provide appropriate training and education;

http://iso27001informationsecurity.blogspot.com/2009/02/what-are-critical-success-factors.html