Information Security Policies - The Legal Risk of Uninformed Personnel.
Verine Etsebeth · 2006
The importance of information security policies are captures by the following quotation: “…the cornerstone of an effective information security architecture is a well written policy statement. This is the wellspring of all other directives, standards, procedures, guidelines, and other supporting documents ” (Peltier 2002). Although the development and deployment of an effective information security infrastructure within the company is imperative to the success of the overall information security discipline, it will be a futile exercise if those people who are expected to maintain and monitor information security in the company do not know what is expected and demanded of them. The importance of information security policies can not be overemphasised as it may be the most cost-effective action a company may take against information security breaches and incidents. The employees of a company may be viewed as the first line of defense when it comes to the early detection of problems. Consequently, employees on all levels of the company must be made aware of the pivotal role security, and specifically information security plays within a company. They need certainty on what their responsibility for information security within the company is, and what will happen if