S 3.44 Making management aware of information security issues

Initiation responsibility: IT Security Officer, Top Management

Implementation responsibility: IT Security Officer

Strong and active support of the top management is essential to the success of security campaigns directed towards the employees. For this reason, it is also essential to make management aware of security issues before starting any information security awareness-raising measures directed towards the employees.

The following presents the most important information needed by management for this purpose:

A suitable starting point for raising the awareness of management is a brief report, followed by a presentation, explaining the subject of information security based on current examples (external and internal examples). The report and presentation could point out that technical safeguards are useless unless personnel and organisational safeguards are implemented simultaneously, for example. To obtain the support of management, it helps to point out the benefits of such safeguards.

By presenting the security risks and alternative solutions, it is possible to convince management of the necessity to implement security safeguards.

According to experience, information security can only be implemented successfully in an organisation if all superiors set a good example. It therefore makes sense to explicitly require all managers to make their employees aware of the security policies and of their obligation to follow them.

Review questions: