• Record all assets
• Conduct risk assessment
• Create infosec policy
• Create policies information assets
• Establish controls to enforce policies
• Identify technology to plug the gaps
• Test the defined controls
• Implement the controls
• Awareness for employees, partners
• Establish a process for reporting non-compliance
• Establish defences periodically
• Conduct system audits, align with emerging threats.
by P