Successful implementation of information security practices requires support and leadership from management. Managers have the responsibility to formulate the strategy for protecting information assets, defining a budget that optimizes corporate information security, and minimizing damage caused by possible attacks. Management uses information security policy to guide and control users' behavior, expressing the values and sets of instructions users must follow. Information security management involves implementing policies, processes, and procedures to secure the organization, including the development of the soft skills necessary to manage the personal and social identities of users to meet business objective. Management efforts aim to teach users the importance of adopting information security practices that are aligned with information security policies