TY - RPRT KW - adaptability KW - Information KW - Information Security KW - information security policy KW - information security programme KW - Organization KW - resources KW - threat KW - vulnerability AU - Michael Dimitrov AB - This report outlines the reasons why each organization needs to adopt an information security policy and an information security programme, emphasising the competitive advantages based on improved adaptation capabilities. First, it examines the concept of information security. On that basis, the author represents possible formulation of organizational objectives. The examination of organizational activities in a competitive context allows to formulate specific ways in which information becomes of utmost significance. The report includes examples demonstrating the need to establish an information security policy and an information security programme, including description of threats and vulnerabilities that, unless adequately managed, could decrease the organizational capabilities to achieve their goals. BT - IT4Sec Reports CY - Sofia DA - December 2013 DO - http://dx.doi.org/10.11610/it4sec.0109 LA - eng M1 - 109 N2 - This report outlines the reasons why each organization needs to adopt an information security policy and an information security programme, emphasising the competitive advantages based on improved adaptation capabilities. First, it examines the concept of information security. On that basis, the author represents possible formulation of organizational objectives. The examination of organizational activities in a competitive context allows to formulate specific ways in which information becomes of utmost significance. The report includes examples demonstrating the need to establish an information security policy and an information security programme, including description of threats and vulnerabilities that, unless adequately managed, could decrease the organizational capabilities to achieve their goals. PB - Institute of Information and Communication Technologies PP - Sofia PY - 2013 T2 - IT4Sec Reports TI - Why the Organization Needs Information Security Policy and Programme ER -