The SABSA Methodology is well regarded for Enterprise Security Architecture, but how can it benefit the implementation and operation of a security program within an organisation? Using a case study, we will outline the creation of a lifecycle for an Information Security Management System, and address the implementation of an holistic approach for managing information through-life. An ISMS should address information risks with a top-down approach into the specific Information Technology areas and provide assurance that risk owners can make informed business decisions. We will address each phase of the SABSA Lifecycle: Strategy & Planning, Design, Implement, and Manage & Measure, showing the Leadership and Governance activities required to execute security processes which meet organisational objectives.Learning Outcomes:Take a holistic approach to developing an ISMSUnderstand and apply the SABSA Lifecycle to your ISMSTraceably provide security value to the enterpriseAllow risk owners to make informed decisionsProvide assurance that your security program supports enterprise objectives