This chapter discusses developing an information security program, including policy development, third-party risk management, and internal partnerships. It covers establishing security policies, assessing and managing risks from third parties, and collaborating internally with teams like legal, HR, IT, facilities, and business units. Developing strong internal partnerships is important for sharing security responsibilities and managing risks across the organization.