Watch this video on YouTube
You've just been appointed as the new Information Security Manager for a company that's never had formal security governance. What's the MOST effective starting point to introduce a security framework?