KevinBeaver
7610 pts. | Feb 18 2009 3:23PM GMT
You definitely need to get the right people on board and determine the underlying business issues before putting a policy in place. Otherwise, it’ll just for show, people will ignore it, and it won’t be enforceable. Effective security policies have the following sections:
#Introduction
#Purpose
#Scope
#Roles and responsibilities
#Policy statement
#Exceptions
#Procedures
#Compliance
#Sanctions
#Review and evaluation
#References
#Related documents
#Revisions
#Notes
Also, check out my other articles on security policies I’ve written for TechTarget and others at <a href="http://www.principlelogic.com" title="http://www.principlelogic. " target="_blank">www.principlelogic.com</a>






