There is an emerging trend from ad hoc information security practices toward more a strategic, programmatic approach to information security. Generally speaking, this means a trend toward more structured, comprehensive and documented information security management plans. This change to programmatic approaches is primarily driven by new laws, regulations and standards. We'll begin with a description of the evolution of these laws, regulations and standards, and their impact on information security, highlighting their increasingly regimented, programmatic nature. The presentation will then culminate in a prediction of what we can expect in the next few years in terms of new requirements placed on information security, and what security professionals can do to prepare for (as opposed to react to) these requirements.