How to Write an Information Security Policy
An Information Security Policy is the cornerstone of an Information Security Program. It should reflect the organization's objectives for security and the agreed upon management strategy for securing information.
Note that the policy production process itself is something that necessarily exists outside of the policy document itself. Documentation with respect to policy approvals, updates, and version control should also be carefully preserved and available in the event that the policy production process itself is audited.
Jennifer Bayuk is an information security consultant and former CISO. She has written or co-edited several books including Enterprise Information Security and Privacy, Stepping Through the IS Audit, 2nd Edition, Stepping Through the InfoSec Program, and a forthcoming work on Security Leadership.
Security



