Senior management sponsorship is provided for the development, maintenance, and enforcement of cybersecurity policies
Polices are an expression of senior managers’ level of commitment to the cybersecurity program. Lack of visible endorsement of cybersecurity policies by senior managers typically renders policies less effective because stakeholders may assume that the policies are not being enforced or that they are simply meant to be used as a guideline rather than a requirement. Senior managers should communicate the importance of cybersecurity policies to the mission and well-being of the organization and express their intention to hold stakeholders responsible for compliance.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: PROGRAM-2a, PROGRAM-2c, PROGRAM-2d.