This document discusses the importance of ongoing maintenance for information security programs. It provides an overview of recommended security management models, such as the ISO model, and outlines key aspects of a full maintenance program including external and internal monitoring, vulnerability assessment, and review procedures. The goal of maintenance is to allow security programs to adapt to changes in threats, assets, vulnerabilities and the internal/external environment over time.
Related topics: