A policy is a foundational aspect to the development of a strong information security program. When developing a policy, you should ensure that you follow a few key principles:
- Receive board-level / CEO approval and support:
- Without CEO or board-level backing, a security program is doomed to fail
- You should only create a policy that you intend to follow:
- This means do not create a policy for the sake of the documentation. A policy that sits on the shelf and is never used does not help anyone.
- Policies that you don't follow will be used by an auditor to show that you are deficient:
- If you have policies follow them.
- Ensure your policies are implementable:
- There are many ways that a security standard can be met, and your ...