Mitigating Risk Exposure

As previously stated, it is impossible to eliminate risk. The goal is simply to mitigate risk. More specifically, the goal is to mitigate risk such that the residual risk is at or below acceptable levels. How can information security policies help? Well-defined security policies balance business requirements and limit behavior. The policy reflects how the business wants to manage its risks. The importance placed on such issues as customer privacy and protecting company secrets directly influences employee behavior.

Security policies must drive a culture that mitigates risk exposure. Policies, and the way they are enforced, reflect the business perception of risk. They are more than just simple business requirements ...

Get Security Policies and Implementation Issues, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.