The report showcases the importance of the Standard of Good Practice for Information Security for an organization. It covers the policies, implementation, attack tree, and legal act in Sri Lanka relating to technology. The report concludes that the effective way to achieve business goals is to employ the Standard of Good Practice in the organization.