The Information Systems Security Officer's Guide: Establishing and Managing an Information Protection Program, Second Edition

We trained hard, but it seemed every time we were beginning to form up into teams, we would be reorganized. I was to learn later in life that we tend to meet any new situation by reorganizing Petronius Arbiter [1]
The objective of this chapter, "Establishing a CIAPP and InfoSec Organization," is to describe how to establish a corporate information assets protection program and its associated organization.
[1]Petronius Arbiter (27 66), Roman satirist. Satyricon (1st century) as quoted in Microsoft's Encarta World.
IWC's information and information systems are some of IWC's most vital assets. These valuable assets must be consistently protected by all IWC employees, contracted personnel, associate companies, subcontractors, and in fact everyone who has authorized access to these assets. They must be protected regardless of the information environment (IE), whether through faxes, telephones, cellular phones, local area networks, Internet e-mails, hard copies, scanners, personal digital assistants any device which processes, transmits, displays, or stores IWC's sensitive information. By sensitive we mean all information that has been determined to require protection. That determination is based on basic, common business sense for example, a marketing plan for next year's product must be protected, and it doesn't take a risk assessment to determine that as well as the use of risk management techniques. Some information must also be protected because there are laws that make that information protection a requirement for example, private information about employees.
In order to provide that consistent protection, those individuals who have authorized access to...