What should the ISMS implementation project manager do to assure success?
• Become familiar with the business you serve. Get to know the department heads and the challenges they face. Try to see information security risks and controls from their perspective. • Cultivate business champions in key areas, for example by talking to sales people on how they win business and what would help them be more successful, or asking R&D people about the importance of keeping research secrets from commercial rivals. • Present ISO27k as a practical solution to current and future business problems rather than an academic set of controls. Solutions are more palatable than controls. • Continue to sell solutions and encourage other managers involved with security to adopt a similar business-focused attitude. • Remember that if the business is to adopt ISO27k and take on board this culture change it should be perceived as empowering and enabling not restrictive and disabling. • Leave out the IT speak and learn business speak. Remember, IT is only part of the ISMS. • Celebrate su