XML Feeds

Search Big4Guy

Custom Search

Sponsored

« CPA's Role in Sarbanes Oxley Auditing Format Conversion and Message Handling - CISA Exam Question Tutorial »

Developing Information Security Policies - Things to keep in mind before developing an Information Security Policy

Developing Information Security Policies - Things to keep in mind before developing an Information Security Policy

One of the keys to better security in the organization is a comprehensive information security policy. A well documented information security policy with senior management support can go a long way in helping the defense indepth cause. Lately, I came across an article in a magazine on four important issues to consider before developing a security policy. The problem most companies face while developing a security policy is to develop a policy which is both implementable and organization specific. The four factors before developing an information security policy are as under:

1. What purpose does the management intend to serve by drafting a security policy? This points at, what is the risk management is trying to address through the security policy?

2. What does the management expect employees or individuals who are accountable to do once the policy is in place? How would management ensure buy-out of the policy at all levels in the organization?

3. What process does the management intend to put in place to ensure conformance with the policy? What monitoring processes would be instated?

4. Finally, management needs to understand the risk of a policy non-complaince. If compliance to policy fails what corrective action does the management intend to take? In other words, what mitigating controls would the management prefer to have?

The above four issues combined can help the management in making an informed decision while formulating information security policies.

Related Posts

Making an Inventory of Information Assets
Auditing Change Controls and Patch Management
Recovery Time Objectives
ISO OSI Presentation Layer


Permalink 03/22/06 09:24:25 pm , by big4guy Email , 276 views, Information Security, Leave a comment »

Feedback awaiting moderation

This post has 23 feedbacks awaiting moderation...

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)