A New Value for Information Security Policy Education
Garry L. White, San Marcos · 2013
Security breaches are a result of poor policies, not the technology used. This paper presents critical issues an information security and assurance policy course should cover. Some of the problems with policies are: 1) failure to address unique systems configurations due to be belief compliance to standards provides full protection, 2) deal with situations that do not yet exist due to new and changing technologies, 3) lack of addressing the external due to globalization and outsourcing, 4) no relationships between security best practices policies and the incidence or severity of security breaches, and 5) the lack of policies being people focus. A good security policy course should teach students how to deal with these problems and write, develop, and implement good policies. These new policies must go beyond required compliance so as to address unique system configurations, deal with the dilemma of security hindering productivity, and finally, focus on people.