Organizations must have controls in place to protect the information that resides within the systems being utilized. The collection of these controls make up the security program. Sometimes it is easier to identify what is not in a security program than what should be in a security program as every organization has different risks, threats, and business drivers. Even though every security program is different, they are usually made up of the same elements. These elements are explained in the first two chapters of your text. Based on these common elements and your own organization’s needs, explain at least three essential information security elements and what you would do to protect your organization against threats using these elements.
After posting your initial response and reading your classmate’s individual organizational needs and protections, respond to two of your peers with your own recommendations based on what you learned from this module’s readings and additional resources.