Previous Topic

Next Topic

Book Contents

Book Index

The Security Policy

In order to meet these challenges, an organization must create and enforce a security policy. A security policy is a set of rules that defines how and by whom sensitive information should be accessed, handled, and distributed, both within and outside of the organization. For example, a security policy may include the following rules regarding visitors who arrive at an enterprise building's lobby:

Other types of security policy rules and measures might be:

An organization's security policy is usually designed by a person who is in charge of handling all security matters for the organization. This person is called a security manager.

In order for a security policy be effective, it must be accompanied by the following measures:

Unfortunately, even when a security policy is accompanied by these measures, its effectiveness is limited against a person with malicious intent.

See Also

Introduction to Information Security

Information is Valuable!

Why Protect Business Information?

Information Security Challenges

Computer and Network Security

Network Security and the Small Business