Article content
In briefShow moreShow lessProsessPilotene collected guidance on information security as management work spanning access, personnel processes and documented responsibility.
- ProsessPilotene collected guidance on information security as management work spanning access, personnel processes and documented responsibility.
- The article collected earlier guidance on organising information security.
- Management needs a view of assets, dependencies and incidents that could interrupt operations.
The explainer
The article collected earlier guidance on organising information security. It connected security work with personnel processes, access management and documented responsibility so that controls become part of normal governance rather than an isolated technical activity.
What this means for the organisation
Management needs a view of assets, dependencies and incidents that could interrupt operations. Prioritised measures should have an owner, deadline and effectiveness check. Regulatory, customer and contractual requirements must be assessed for the particular organisation.
The explainer placed security responsibility with management and connected it to assets, threats, personnel processes and supplier requirements. A management system brings controls, documentation and follow-up together, but effectiveness depends on prioritising and testing measures. This makes security part of ongoing governance rather than a separate technical checklist.
The Norwegian National Security Authority’s principles organise security work around identifying, protecting, detecting and responding. The vendor-independent framework provides a professional check on ProsessPilotene’s practical advice. The article describes organisational work; the NSM source shows how measures fit into a coherent, prioritised security programme.
The work can be made concrete through an inventory of critical assets, owners, dependencies and prioritised measures. Management needs reporting on implementation and tested effectiveness, not merely that a control exists on paper. Incidents, exercises and exceptions provide evidence for changing priorities as threats or the organisation evolve.
Sources
Primary source: ProsessPilotene, “Hvordan sørge for god informasjonssikkerhet i din organisasjon?,” 28 June 2024 (Norwegian).
Norwegian National Security Authority, ICT security principles version 2.0, 16 April 2020.
Further reading
How does ProsessPilotene work with information security?
Join the discussion
Which experience from your own organisation is most relevant to this story? Share what you learned.

