The tone at the top must be conducive to effective security governance. It is up to senior management to set a positive
example in this regard, as lower-level personnel are much more likely to abide by security measures when they see
their superiors respecting the same measures as well. Executive management’s endorsement of security requirements
ensures that security expectations are met at all levels of the enterprise. Penalties for noncompliance must be defined,
communicated and enforced from the board level down.