Management of Information Security, Fourth Edition 4-3
6. Introduce students to the bull’s-eye model for prioritizing complex changes, and list the
four different layers of the model:
7. Explain the role of policy in protecting an organization and its employees, by
Policy, Standards, and Practices
1. Describe policy as a defined plan or course of action, intended to influence and
determine decisions, actions, and other matters. Note that policy represents the formal
statement of the organizations managerial philosophy.
5. Point out that practices, procedures, and guidelines determine how employees are to
comply with policy.
6. Describe the three types of policies that must be defined, according to NIST, and note
that they are often created in this order:
Enterprise Information Security Policy
1. Define an enterprise information security policy (EISP) as a policy that sets the
strategic direction, scope, and tone for all of an organization’s security efforts.
Integrating an Organization’s Mission and Objectives into the EISP
1. Educate students on the role of the EISP in stating the importance of information
EISP Elements
1. Discuss what elements should exist within an EISP document: