The organisation should establish a management level security forum to oversee the ISMS, meet periodically, maintain formal minutes and include the head of security as a member.
The security department should develop and implement security strategies and action plans, and review security processes covering information, communications, physical infrastructure and operational processes. The head of security should be responsible for recommending security policies and changes.