If you align IT objectives, establish IT governance, manage IT risk and measure IT performance, you will get the most out of your organization’s investment in information technology
Ylber Limani I would prefer to connect it with cybersecurity and IT governance. In the digital era, all major security risks are cyber related and the governance mechanisms adopted by organizations play a key role in influencing the tangible and intangible security elements. The effect of these mechanisms get reflected in the market value of organizations assets and firm performance.
Infosec effectiveness and efficiency lie with the governance infrastructure, policies, and compliance. http://iosrjournals.org/iosr-jce/papers/Vol12-issue3/N012396102.pdf
you can adopt a policy regulated framework to your information security system . See how I adopted it to e-commerce: Article The Use of Policy Regulated Frameworks to Secure Mobile Commerce
The most effective and efficient information security systems are systems that have a management system and are built in accordance withthe requirements of ISO/IEC27001, based on a "process approach" and using risk management