Ravi Char made an excellent post where he discusses the impact of Information security on a company. He uses the Maslow hierarchy as a model, and adds the layers of security required.
The nice thing about this model is the visualization of the requirements of each level. You will not be able to reach the top of the pyramid unless you fulfill each previous steps.
His model looks like this:

Ravi gives a nice explanation of each required step. He uses examples to relate the descriptions to companies and stages. I like it.
I see a lot of different companies in all stages. What I notice is that most companies of a certain age and size do have security, but at the management level, they are on the first step - "Don't care for security". This is where I focus. To get managers to understand, care and use security.

Delicious
StumbleUpon
Reddit
Facebook
Google
Yahoo
Post new comment