Summary

To ensure the systems and networks are protected, compliance and enforcement policies define what could happen when policy is broken. Compliance and enforcement policies tend to fall outside the technical arena in which most security professionals work. These policies require knowledge of various corporate policies as well as compliance to various laws, including intellectual property, labor, and possibly criminal law.

  1. Testing and effectiveness of the policies:

    • Compliance is a very subjective process. Policies in this section will cover the notification and report processes with your measurements.

    • Management should encourage security-awareness training so that everyone in the organization understands the policies and their impact. ...

Get Writing Information Security Policies now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.