Security Policy Guidelines
Michel E. Kabay, Bridgitt Robertson · 2012
This chapter describes guidelines on how to express security policies effectively. Security policy governs how an organization's information is to be protected against breaches of security; examples include policies on identification and authentication, authorization for specific kinds of access to specific data, and limitations on the use of corporate resources for email and Internet access. An increasingly popular standard for writing and implementing security policies, especially in Europe, is ISO/IEC 27002:2005, which is the current version of ISO/IEC 17799:2005, in turn based on the old BS7799. The chapter emphasizes that if one is setting out to create policy de novo, it is important to use an existing policy template. Creating policies without guidance from experienced policy writers is a time-consuming, frustrating job that can consume thousands of hours of time. Security policies should be written with clear indications that all employees are expected to conform to them. Language should be definite and unambiguous.