Sangkyun and Choon proposed a framework for security of information systems which emphasizes on the designing of controls for information security, provide the steps and tools for planning and aligns the security strategy with other strategies [4]. However, in order to make this strategy work, there is a need to develop a lower-level process model which can provide a step by step guidance to the organization. Also it requires the development of evaluation model for security controls.