Enforcing information security: architecture and responsibilities
Steven J. Ross · Network Security · 2008
True information security – the actual, demonstrable and continuous protection of information resources – exists within an organisation at the intersection of the ideal and the possible. Information security policies and standards express management's intent; the procedures and technology in place to accomplish the policies and standards are a more accurate representation of an organisation's commitment to security. If the road to hell is paved with good intentions, the path to heaven (or at least a good night's sleep by senior management) is built of many individual stones that collectively add up to the information security programme.