Developing the Security Charter
Purpose and Foundation
Last Updated: March 9, 2026The Security Charter is the governance instrument that transforms the obligations and authority established by the security mandate into a tangible, context-specific framework for action....
Elaborate Goals and Scope
Last Updated: March 9, 2026The security mandate establishes what the organisation is obligated to achieve. The security charter builds on that foundation by defining what the information security programme...
Setting up Guiding Principles
Last Updated: March 9, 2026A well-constructed security charter is only as effective as the principles that underpin it. The guiding principles establish the philosophical and operational foundation from which...
Developing the Mission Statement
Last Updated: March 9, 2026The mission statement is the most concise and enduring expression of the security programme’s purpose. It articulates why the security function exists, what it is...
Consider Legislation and Compliance Obligations
Last Updated: March 9, 2026While the instinct to begin information security strategy with technology is understandable, the most rigorous and defensible starting point is legal compliance. Regulatory obligations define...
Claim Enterprise-wide IS Decision Authority
Last Updated: March 9, 2026A security charter that limits the ISO’s involvement to the boundaries of the information security function misunderstands the nature of information security risk and the...
