Information Security Plan for SMEs: How to Design It in 5 Phases
1. Introduction The Information security plan is the most important document an SME can commission in cybersecurity, and at the same time the least understood. While large corporations have been managing security with methodology for decades, most small and medium businesses operate with loose measures: an antivirus, an office firewall and plenty of trust. An Information security plan properly designed transforms that improvisation into a system: identified assets, prioritized risks, approved policies and a budget you can defend to the board. In this article we explain how to design an Information security plan in five phases, using the real document …

