Chapter 1. What Information Security Policies Are

A CLIENT CALLED ME UP ONE DAY AND asked me to come to his office. Once I arrived, he asked me to install a firewall so that his network would be secure. I asked him for his company’s security policy so I could configure the firewall. He gave me a curious look and asked, “What do I need that for?”

In the years since the explosion of the Internet, this response is still the rule rather than the exception. Companies have comprehensive employee policies, sometimes filling two-inch binders, but do not have information security policies. If they do, they will hand you 5 sheets of paper that cover ...

Get Writing Information Security Policies now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.