Despite its importance, there is little research on how organizations perceive information security management. This study classified critical success factors in information security management at the organizational level. A performance model was designed to empirically test the validity of these factors. Data were collected through an online questionnaire from prominent information technology managers and specialists who worked in Saudi organizations and contributed to decision making about information security. The data were analyzed using structural equation modeling. The selected constructs—business alignment, top management support, information security awareness, and security controls—appeared to significantly influence information security management, with the balanced scorecard shown as an effective way of measuring performance.