This session will look at an IT security program from a slightly different perspective. It’s not a question of if, but when, an IT security leader will need to demonstrate that they have provided a defensible, holistic security program. This session will look at examples of potential problems which could negatively reflect on the organization, and the corresponding ways to mitigate. This session will also look at the pillars of the information security office and see where the potential gaps are usually found. Lastly, we will dissect the information governance and privacy concerns which in many ways are fundamental to the cyber forensic and investigative processes associated with the information security office. Attendees will learn; How can we quantify if an information security program is in fact reasonable?; How are security leaders able to monitor and investigate individuals or incidents and ensure we are not adding undo risk to the organization?; and A few lessons learned from leading a security office while under the world's largest spotlight.