What two things must be achieved to secure information assets successfully?
According to Sun Tzu an organization should know itself and know its enemy. This means that all managers from the three communities of interest in an organization must know how its information is processed, stored and transmitted, and identify what resources are available, in order to know itself. This will help to implement an in-depth risk management program by implementing safeguards, controls, and other mechanisms which should be maintained and kept current. This also implies that an organization should locate the weaknesses of the organizations operations, and recognize them as the potential enemy. By discovering and assessing the risks of the organization, operations managers can determine how those risks can be controlled or mitigated. The levels of risk should be identified and assessed.