The management of information risk has become a significant topic for all organizations, small and large alike. But for the large, multi-divisional organizations, it poses the additional challenge of determining how to deploy an information security governance program among what are often disparate business units. The best of both models is achieved by providing for a central governance body focused on program results, while the business unit has control over the methods. Following describes how the establishment of a hybrid program and sharing of responsibilities might be realized.”]

