ABSTRACT

As security professionals, we often take the view that the overall objective of an information security program is to protect the integrity, confidentiality, and availability of that information. Although this is true from a security perspective, it is not the organization objective. Information is an asset and is the property of the organization. As it is an asset, management is expected to ensure that appropriate levels of control are in place to protect this resource.