Home > Ask the Information Security Experts > Information security governance and risk management Questions & Answers > How to write an information security policy
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

How to write an information security policy

>
QUESTION:
I've been assigned to write an enterprise security standard. Where do I start, what is the procedure, and what are some common mistakes?


RELATED CONTENT
Information security governance and risk management
Will physical security integrators work with IT departments?
How to manage logs
Credit card data protection (over the phone)
What are best practices for credit cards in a call centre?
Complying with the UK Data Protection Act of 1998
How to achieve laptop data security

Security Policies and User Awareness
Cloud-based services require stalwart business continuity plans
Preventing phishing attacks: Enterprise best practices
CISOs take measured steps to reduce social media risks
Increasing information security awareness in the enterprise
How to develop a culture of security in the enterprise
Creating and enforcing a clear-desk policy
Physical security threats: Don't gift your data away
Cut down on calls to help desk with cybersecurity awareness training
Layoffs prompt insider threat fears, cybersecurity survey finds
Essential guide: Pandemic planning for H1N1

IT Security Frameworks and Standards
How to develop a culture of security in the enterprise
ICO issues draft guidelines for personal information online
Using a privacy impact assessment template for DPA compliance
Benefits of ISO 27001 and ISO 27002 certification for your enterprise
The elements of a compliance-oriented architecture
New products aim to streamline compliance efforts
A helpful BSI data protection standard for DPA compliance
How project management maturity models can reveal security strength
Consider a compliance-driven security framework
CSA, Jericho Forum unite on cloud computing security message

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Neil O'Connor EXPERT RESPONSE FROM: Neil O'Connor

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site
ANSWERED October 2009:
I assume that you mean how to write a security policy. One of the key controls in ISO 27001, a technology-neutral information security standard, is having an organisational security policy endorsed by senior management. In my experience, if you want to get senior management to sign something that the whole organisation can see, it's best to keep it short! It should cover the organisation's commitment to security, including who is responsible for infosec tasks. The policy should also provide a pointer to more detailed documentation and guidance, and cover the key security requirements that the organisation is going to meet, like the Data Protection Act, for example.

Beyond that, policy documentation is very specific to the organisation. I do not believe that one set of documentation fits all organisations, but the security policies and procedures need to fit the organisation's culture if they are going to have any effect.

However you decide to frame the security policy, here are key questions that you need to consider:

  • What are your security objectives, and how do you measure them?
  • What types of information do you handle, and how do the different types of information need to be protected?
  • How do you assess risks and select security controls?
  • How do you manage and report incidents, and learn from them?
  • Who is responsible for security?
  • What is acceptable employee use for Internet, email and other communication channels?




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Access Management: Authentication, Biometrics, Password Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts