Introduction

This chapter discusses the structure of a complete security policy. Although all security policies are different, they all share several central themes. In this chapter, we discuss which common areas a security policy should cover. We also cover industry- and organization-specific areas. As you study the material in this chapter, remember that a security policy is a set of proposals designed to ensure a secure operational environment. These proposals vary from friendly suggestions to mandatory rules you must follow, most of which are the latter. It is more important for you to understand the security policy concepts and their applicability to an organization than it is for you to memorize a list of policy components.

Consider any ...

Get Security+ Training Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.