As a policy maker ,the prime responsibility would be to set the information resource security policy for the organizations objective. It should be aligned to reducing risks, compliance with the law and regulations and assurance of operations. It should also maintain information integrity and confidentiality.
The basic rules to follow when shaping a policy
- Never conflict with law
- Stand up in court
- Properly sported and administered
- Contribute to the success if the organization
- Involve end user of information systems
Characteristics of an effective policy
For a policy to be effective as expected, they must achieve the below.
- Properly disseminated.
- Well read.
- Understood.
- Agreed to it.
Now lets get to know about a brief understanding about the types of effective policies.
These are the 3 types if information security policies that have been defined.
- Enterprise inforsec program policy
- Issue specific inforsec policies
- System-epsecific inforsec policies.
No comments:
Post a Comment