Talk With an Expert

Creating an IT Security Awareness Program for Senior Management

Creating an IT Security Awareness Program for Senior Management (PDF, 1.66MB)Published: 08 May, 2003
Created by
Robert Nellis

This paper will present an approach to creating and deploying a security awareness program with senior management as the intended audience. This paper is intended as a guideline to creating a successful security awareness program for your organization. A successful program for senior management is the key to the security program for the entire organization and therefore needs to be carefully and concisely constructed. Creating the program requires numerous resources, a clear understanding of security within the organization and an understanding of the position of senior management on IT security. This paper will outline the steps necessary to identify the current level of senior management's IT security knowledge. Once the knowledge level is identified the steps to develop the content of the awareness program based on this knowledge will be discussed. The paper will provide recommendations on data gathering, risk analysis, resource requirements and how to correlate the information to the impact that is has on the organization. Options for presenting the program to senior management and ongoing communication recommendations will also be discussed.