Information Security Policy Framework: Best Practices for Security Policy in the E-commerce Age

Malcolm E. Palmer, Craig Robinson, Jody Patilla, Edward P. Moser · Information Systems Security · 2001

An information security policy framework provides an organization with a concise yet high-level and comprehensive strategy to shape its tactical security solutions in relation to business objectives. Moreover, it clearly defines the value of information assets, represents organizationwide priorities, and definitively states the underlying business requirements and assumptions that drive security activities. By going through the process of developing a relevant, usable policy framework, an organization can make the difficult decisions on the information security program up front, and make implementation of the rest of the program that much easier. In addition, an organization that regularly reviews and assesses its current policy implementation can identify key missing and ineffective elements within its information security program.

Read the paper · More papers on PaperTik