Похожие презентации:
Information_Security_Management_Presentation
1.
INFORMATION SECURITYMANAGEMENT
A Discipline in Alignment
Author: [Your Name]
Course: Information Security Management
2026
ALIGN
STRATEGY
Information Security Management • 2026
2.
Agenda• Introduction: The Alignment Challenge
• Disciplined Alignment Framework
• Managerial Stress and Security
• Security Management Maturity
• The CIA Triad
• Technical Controls
• Governance and Policy
Information Security Management • 2026
02
3.
The Alignment Problem03
SECURITY
PRACTITIONERS
BUSINESS LEADERS
THE RESULT
Focus on technical controls
Prioritize operations and revenue
A disconnect between security
and business priorities
Tools, systems,
vulnerabilities, and
operational protection.
Growth, continuity,
customers, and financial
performance.
Source: Disciplined Alignment Research, 2025
Information Security Management • 2026
→ Gaps in decision-making
→ Vulnerabilities
4.
What is Disciplined Alignment?04
A framework for integrating security with business strategy.
01 OBJECTIVE RISK
ASSESSMENT
Standardized, validated risk
evaluation.
Information Security Management • 2026
02 ENTERPRISE
ARCHITECTURE
Embed security directly into
system design.
03 BENEFIT REALIZATION
Demonstrate security's business
value.
5.
Types of Security Stress05
Security-Related Stress (SRS) in Managers
CHALLENGE STRESS
HINDRANCE STRESS
Problem-focused coping
Emotion-focused coping
↓
Positive outcomes
↓
Negative outcomes
Key finding: Information security knowledge is the #1 predictor of performance.
Information Security Management • 2026
6.
Stress Coping Framework06
Stressor → Coping → Response → Outcome
CHALLENGE STRESS
HINDRANCE STRESS
Active Problem-Solving
Avoidance / Denial
→ Better Security
→ Worse Security
Organizational support moderates these relationships.
Information Security Management • 2026
7.
Security Management Maturity07
Adaptation
Culture
Strategy
Perception
Evolve with threats
Shape security
behavior
Strategic priority
Role-based differences
Resources
Remote Work
Compliance
Budget & staffing
New security
challenges
Regulatory balance
Information Security Management • 2026
8.
The CIA Triad08
Foundational Security Model
CONFIDENTIALITY
INTEGRITY
AVAILABILITY
Encryption
Hash Functions
Redundancy
MFA
Access Control
Digital Signatures
Disaster Recovery
BALANCE IS ESSENTIAL
Information Security Management • 2026
9.
Access Control09
Three-Step Process
IDENTIFICATION
AUTHENTICATION
AUTHORIZATION
Who
Prove it
What can they do?
RBAC • Role-Based Access Control
Information Security Management • 2026
ABAC • Attribute-Based Access Control
10.
Security Controls Overview10
Layered Defense
Network
Access
Firewalls • IDS • Segmentation
Authentication • Authorization
Cryptographic
Endpoint
Encryption • PKI
Antivirus • EDR
Information Security Management • 2026
11.
Policy Development Phases11
01
02
03
04
05
Project
Initiation
Policy
Development
Consultation
and Approval
Awareness and
Education
Policy
Dissemination
Information Security Management • 2026
12.
Risk Management Process12
STEP 01
STEP 02
Identify business assets
Recognize risks
STEP 03
STEP 04
Determine impact severity
Analyze vulnerabilities
Document all findings in a risk analysis report.
Information Security Management • 2026
13.
Current Challenges13
01
02
Alignment Gap
Managerial Stress
03
04
Rapidly Evolving Threats
Resource Constraints
Information Security Management • 2026
14.
Emerging Technologies14
01
02
Zero Trust Architecture
Post-Quantum Cryptography
03
04
Confidential Computing
AI-Powered Security Operations
NIST CSF 2.0 provides a framework for adoption.
Information Security Management • 2026
15.
Key Takeaways• Align security with business strategy
• Support managers in security decisions
• Assess maturity continuously
• Balance CIA triad priorities
• Govern through clear policies and procedures
SECURITY IS A BUSINESS DISCIPLINE — NOT JUST A TECHNICAL FUNCTION.
Information Security Management • 2026
15