Security management

From Wikipedia, the free encyclopedia

See also: ITIL Security Management

for test Security management: In network management, the set of functions (a) that protects telecommunications networks and systems from unauthorized access by persons, acts, or influences and (b) that includes many subfunctions, such as creating, deleting, and controlling security services and mechanisms; distributing security-relevant information; reporting security-relevant events; controlling the distribution of cryptographic keying material; and authorizing subscriber access, rights, and privileges.

Source: From Federal Standard 1037C and from MIL-STD-188

In a more general management context, Security management entails the identification of an organization’s information assets and the development, documentation and implementation of policies, standards, procedures and guidelines.

Management tools such as information classification, risk assessment and risk analysis are used to identify threats, classify assets and to rate system vulnerabilities so that effective control can be implemented.