ABSTRACT

An organization’s information security policy is one of the most important business documents within the organization. That’s right-business document and not a technology document. The security policy should always be an extension of the organization’s business environment, culture, and mission as well as account for any applicable laws and regulations. By having a formal information security policy, the organization will benefit in a number of ways.