Explaining the role and importance of Information Security in the organization, especially to management, can be a difficult task. I have lost count of the number of times in my career where, ten or fifteen minutes into a presentation on IS, I have looked up to find one half of my audience asleep and the other half clueless. As a result, I often rely on the following seven simple objectives and explain that, if you can answer “yes” to each of these rules at the end of the day, then you have succeeded in creating a solid information security organization: