Sunday, July 31, 2005

Why a Security Policy Is Necessary

Here is why:
  • Policies enable management to make a statement about the value of info to the business
  • Policies can permit actions that would otherwise backfire
  • A policy is necessary to define what constitutes appropriate behavior
  • A policy provides fondation for prosecution or human resources action

Howerver, none of these are really the main management driver behind policy. Management likes policies that provide a shield. A policy largely is legal risk management; it is how senior management keeps the corporation from the legal wrongdoing of a few bad apples.

Adopted from Protect Your Windows Network : From Perimeter to Data by Jesper M. Johansson, Steve Riley.


Post a Comment

<< Home