The development of a good security program is simply a matter of following some basic procedures similar to those applied to all aspects of the business planning process.
The answers to the questions about your customers' needs and requirements regarding security will drive the development cycle of your security plan and provide a clear idea of your security objectives and what should underpin them.
The Security Program Lifecycle (SPL) involves the following steps:
- Analyse/assess
- Design
- Implement
- Maintain/monitor
- Continuous improvement