This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission. Implementing an Information Security Program Recently, there has been an increase in the awareness for the need within corporations (as well as within government agencies) to protect sensitive, proprietary and company secret information. Unauthorized modification, loss or compromise of such information could very well severely damage an organization's current operations; future or even put it out of business. However, the largest threat to an organization's computer information systems and the data they contain remains the trusted or authorized user. Since wide s... Copyright SANS Institut