-
Book Overview & Buying
-
Table Of Contents
Executive's Cybersecurity Program Handbook
By :
The vision of the office of information security is to secure the organization while making security a second thought.
Many organizations tend to throw technology at a problem, but is that the right solution? What is the goal of the company’s information security program? What will make you and your team stand out as a force for delivering top-notch security services? As a security leader, you must first understand where you are and where you want to go. If you do not have an end goal, how will you know how to get there?
A vision statement is a high-level description of how the program strives to achieve success. For instance, the preceding quote is a vision statement that could be used for a security department. It is intended to not only state the purpose of the department but the overall goal. A phrase I like to use for our security program is “Employees already think of cybersecurity as a second thought – I intend to keep it that way.”
Why is that statement important to me and our program? We want our security program to be as robust as possible and protect our systems and data while keeping our users safe. Information security should enable while making it easy for those who are not technically savvy. It should be as transparent as possible without always being in your face. Users should not have to read an entire manual to learn how to do their jobs, which are already tough without adding more layers on top.
The vision statement should depict what is most important to the department or organization. It should not be lengthy―only three sentences or fewer, but make it meaningful. It can be internal or external customer-facing, but make it a way of marketing yourself to others. As the security field is dynamic, a vision statement does not have to remain static and can evolve over time. One could write a vision statement and a few years down the line, decide to change it.
Here’s an example of a vision statement:
The Institute for Information Security & Privacy (IISP) at Georgia Tech is as an international leader in researching, developing, and disseminating technical solutions and policy about cybersecurity and privacy. We assemble strong, innovative, multi-disciplinary teams to address contemporary and future cybersecurity or privacy challenges faced by government, industry and individuals. Our graduates become leaders in government, scientific, industry and entrepreneurial communities.
—Georgia Tech University (https://www.scs.gatech.edu/research/institutes-centers)
There is no right way or wrong way to create a vision statement for your department. With one in place, however, it provides context for the goals and objectives that the department strives to achieve. It also shows that the department takes cybersecurity seriously in the types of services it will provide to its customers.
While vision statements are important for providing context for what the department strives to achieve, mission statements are equally as important. Mission statements depict why the department exists.