Policies alone do not constitute a sufficient awareness effort
Charles Cresson Wood · Computer Fraud & Security · 1997
While information security policies are a fundamental expression of management's intentions on which many other information security efforts are built, they are, by themselves, not a sufficient awareness effort. Many managers erroneously believe that all they need to do is write and publish a set of policies, and the awareness issue will be sufficiently handled. They fail to acknowledge the importance of: 1) consistent and regular enforcement, 2) explicit procedures to handle exceptions, 3) visible management support, 4) sufficient resources for implementation, and 5) specific staff awareness reinforcement programmes. This article will explore common management misconceptions about policies and how the information security practitioner can overcome these misconceptions. A list of tools and techniques for raising the level of awareness about information security is included.