The information security program implementation guide by National Institute of Standards and Technology (NIST) provides a broad overview of information security program components and assists information security managers in understanding how to develop and implement an information security program based on the minimum government security requirements. The Information Security Handbook: A ...
The information security program lifecycle must have an exact assignment of roles and responsibilities concerning security. It should be noted that information security awareness training is a critical element of the strategy because users are often the weakest security link.