
July 21st, 2008, 06:40 PM
|
|
Guest
|
|
Posts: n/a
Time spent in forums:
Reputation Power:
|
|
|
Information Security in Mergers and Acquisition
Alfred,
I would start with:
1) A gap analysis document between buyer's and acquirer's security policies.
2) For each of the organizations - a gap analysis between "actual" policies and procedures and the "written" security policies.
3) Based on the above documents (and management input) put a "new" security policy and get management sign-off.
4) Put a plan of what's required to be done for each "organization" to adopt the merged security policy.
it is easy said than done!
Ido
|