Developing an Enterprisewide Policy Structure
Thomas R. Peltier · Information Systems Security · 2004
As security professionals we often view the overall objective of an information security program as that of protecting integrity, confidentiality, and availability. While this is true from a security perspective, it is not the organization's objective. Information is an asset and is the property of the organization. As an asset, management is expected to ensure that an appropriate level of control is in place to protect this resource.